You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package (implicit)
name:my-package (explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true (prereleases)
prerelease:false (no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search by last download date:
last_downloaded:<"30 days ago"
last_downloaded:>"August 14, 2022 EST"
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Search queries for all Generic-specific package types
Search by file path:
generic_filepath:path/to/file.txt
Search by directory:
generic_directory:path/to
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo for negation
For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching
For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Generic,
Go,
Helm,
Hex,
HuggingFace,
LuaRocks,
Maven,
MCP,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
VSX,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
istioctl
7f8809b1ca91dbf1099563c1373…
One-liner (summary)
Description
This package was uploaded with the following V2 Distribution manifest:
{"schemaVersion":2,"mediaType":"application/vnd.docker.distribution.manifest.v2+json","config":{"mediaType":"application/vnd.docker.container.image.v1+json","size":1638,"digest":"sha256:dbe577def550d28783e6fea861ed2c93088169cb061e158552ab3f732d717b7f"},"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":40605316,"digest":"sha256:777ae9ae6f12880ccb9af5e5c875d80819099c91a0ffca7afa246edb48cce083"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":28876327,"digest":"sha256:b8ffa4af3b70f3c6fb07c65e65cd8316d532c1daa681b17e70ac7de65d2ad423"}]}
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG MICRO |
32 bytes | ||
|
Digest:
sha256:777ae9ae6f12880ccb9af5e5c875d80819099c91a0ffca7afa246edb48cce083
Command: COPY /micro . # buildkit |
38.7 MB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER 1000:1000 |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH |
32 bytes | ||
|
Digest:
sha256:b8ffa4af3b70f3c6fb07c65e65cd8316d532c1daa681b17e70ac7de65d2ad423
Command: COPY arm64/istioctl /usr/local/bin/istioctl # buildkit |
27.5 MB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/istioctl"] |
32 bytes |
Last scanned
9 hours ago
Scan result
Vulnerable
Vulnerability count
68
Max. severity
High| Target: | LYOKU3ycHRyM.sbom-cyclonedx.json (redhat 9.8) | |
| HIGH |
CVE-2026-11352: curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerabilityAn issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| HIGH |
CVE-2026-11586: curl: curl: Denial of Service via WebSocket PING floodBy default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| HIGH |
CVE-2026-8286: curl: curl: Insecure connection establishment due to TLS configuration mismatchA vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| HIGH |
CVE-2026-8925: curl: curl: Double-free vulnerability in SASL authenticationThe curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| HIGH |
CVE-2026-9547: curl: curl: Man-in-the-middle attack via SSH host key bypassWhen a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| HIGH |
CVE-2026-11352: curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerabilityAn issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| HIGH |
CVE-2026-11586: curl: curl: Denial of Service via WebSocket PING floodBy default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| HIGH |
CVE-2026-8286: curl: curl: Insecure connection establishment due to TLS configuration mismatchA vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| HIGH |
CVE-2026-8925: curl: curl: Double-free vulnerability in SASL authenticationThe curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| HIGH |
CVE-2026-9547: curl: curl: Man-in-the-middle attack via SSH host key bypassWhen a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-42250: bzip2: bzip2: Denial of Service in bzip2recover via a specially crafted filebzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67Package Name: bzip2-libs Installed Version: 1.0.8-11.el9 Fixed Version: References: access.redhat.com cert.pl inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-56391: coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte inputGNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.Package Name: coreutils-single Installed Version: 8.32-41.el9_8 Fixed Version: References: access.redhat.com cert.pl git.savannah.gnu.org git.savannah.gnu.org nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-56392: coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop valuesGNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35dPackage Name: coreutils-single Installed Version: 8.32-41.el9_8 Fixed Version: References: access.redhat.com cert.pl git.savannah.gnu.org git.savannah.gnu.org nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2025-13034: curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonationWhen using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the public key of the server certificate to verify the peer. This check was skipped in a certain condition that would then make curl allow the connection without performing the proper check, thus not noticing a possible impostor. To skip this check, the connection had to be done with QUIC with ngtcp2 built to use GnuTLS and the user had to explicitly disable the standard certificate verification.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se github.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2025-14017: curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfersWhen doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-11856: curl: curl: Information disclosure via incorrect Digest authentication header reuseSuccessfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-1965: curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authenticationlibcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work. An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it just sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1... The set of authentication methods to use is set with `CURLOPT_HTTPAUTH`. Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API).Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-3783: curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirectWhen an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` keywords, curl would pass on the bearer token set for the first host also to the second one.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-3784: curl: curl: Unauthorized access due to improper HTTP proxy connection reusecurl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com cert-portal.siemens.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-4873: curl: curl: Information disclosure due to incorrect TLS connection reuseA vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-5545: curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuselibcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-5773: curl: libcurl: Wrong file transfer due to incorrect SMB connection reuselibcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should. This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-6253: curl: curl: Proxy credential disclosure via redirects to unauthenticated proxiescurl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow a redirect to a URL using another scheme (say `https://`), accessed using a second, different, proxyPackage Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-6429: curl: libcurl: Credential leak via reused proxy connection during HTTP redirectsWhen asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-7168: curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuseSuccessfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-8924: curl: curl: Cookie injection via malicious HTTP server using super cookiesA flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-8926: curl: curl: Information disclosure via incorrect .netrc password lookupWhen asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-41991: gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utilityGNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269Package Name: gzip Installed Version: 1.12-1.el9 Fixed Version: References: access.redhat.com cert.pl cgit.git.savannah.gnu.org nvd.nist.gov ubuntu.com www.cve.org www.gnu.org |
|
| MEDIUM |
CVE-2026-11850: krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds readAn integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.Package Name: krb5-libs Installed Version: 1.21.1-10.el9_8 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-54371: attr: Symlink Traversal Privilege Escalation via getfattr and setfattrattr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.Package Name: libattr Installed Version: 2.5.1-3.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com cgit.git.savannah.nongnu.org cgit.git.savannah.nongnu.org nvd.nist.gov security.access.redhat.com www.cve.org www.vulncheck.com |
|
| MEDIUM |
CVE-2025-13034: curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonationWhen using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the public key of the server certificate to verify the peer. This check was skipped in a certain condition that would then make curl allow the connection without performing the proper check, thus not noticing a possible impostor. To skip this check, the connection had to be done with QUIC with ngtcp2 built to use GnuTLS and the user had to explicitly disable the standard certificate verification.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se github.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2025-14017: curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfersWhen doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-11856: curl: curl: Information disclosure via incorrect Digest authentication header reuseSuccessfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-1965: curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authenticationlibcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work. An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it just sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1... The set of authentication methods to use is set with `CURLOPT_HTTPAUTH`. Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API).Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-3783: curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirectWhen an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` keywords, curl would pass on the bearer token set for the first host also to the second one.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-3784: curl: curl: Unauthorized access due to improper HTTP proxy connection reusecurl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com cert-portal.siemens.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-4873: curl: curl: Information disclosure due to incorrect TLS connection reuseA vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-5545: curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuselibcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-5773: curl: libcurl: Wrong file transfer due to incorrect SMB connection reuselibcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should. This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-6253: curl: curl: Proxy credential disclosure via redirects to unauthenticated proxiescurl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow a redirect to a URL using another scheme (say `https://`), accessed using a second, different, proxyPackage Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-6429: curl: libcurl: Credential leak via reused proxy connection during HTTP redirectsWhen asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-7168: curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuseSuccessfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-8924: curl: curl: Cookie injection via malicious HTTP server using super cookiesA flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-8926: curl: curl: Information disclosure via incorrect .netrc password lookupWhen asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: access.redhat.com curl.se curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-58055: nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requestsnghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.Package Name: libnghttp2 Installed Version: 1.43.0-6.el9_8.1 Fixed Version: References: access.redhat.com github.com github.com nvd.nist.gov ubuntu.com www.cve.org www.vulncheck.com |
|
| MEDIUM |
CVE-2025-5372: libssh: Incorrect Return Code Handling in ssh_kdf() in libsshA flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.Package Name: libssh Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com www.cve.org www.libssh.org |
|
| MEDIUM |
CVE-2026-3731: libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handlerA weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.Package Name: libssh Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com gitlab.com nvd.nist.gov ubuntu.com vuldb.com vuldb.com vuldb.com www.cve.org www.libssh.org www.libssh.org |
|
| MEDIUM |
CVE-2026-59843: libssh: libssh: denial of service via zero advertised channel packet sizeA flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.Package Name: libssh Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59844: libssh: libssh: denial of service via oversized SFTP read lengthA flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.Package Name: libssh Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59845: libssh: libssh: denial of service via unchecked ProxyCommand fork() failureA flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.Package Name: libssh Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59847: libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verificationA flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.Package Name: libssh Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59848: libssh: libssh: denial of service via SFTP responses with unknown request IDsA flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.Package Name: libssh Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59850: libssh: libssh: use-after-free via data callbacks on closed channelsA flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.Package Name: libssh Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2025-5372: libssh: Incorrect Return Code Handling in ssh_kdf() in libsshA flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.Package Name: libssh-config Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com www.cve.org www.libssh.org |
|
| MEDIUM |
CVE-2026-3731: libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handlerA weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.Package Name: libssh-config Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com gitlab.com nvd.nist.gov ubuntu.com vuldb.com vuldb.com vuldb.com www.cve.org www.libssh.org www.libssh.org |
|
| MEDIUM |
CVE-2026-59843: libssh: libssh: denial of service via zero advertised channel packet sizeA flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.Package Name: libssh-config Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59844: libssh: libssh: denial of service via oversized SFTP read lengthA flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.Package Name: libssh-config Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59845: libssh: libssh: denial of service via unchecked ProxyCommand fork() failureA flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.Package Name: libssh-config Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59847: libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verificationA flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.Package Name: libssh-config Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59848: libssh: libssh: denial of service via SFTP responses with unknown request IDsA flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.Package Name: libssh-config Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-59850: libssh: libssh: use-after-free via data callbacks on closed channelsA flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.Package Name: libssh-config Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-58058: nmap: Nmap: Denial of Service via crafted IPv6 responseNmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.Package Name: nmap-ncat Installed Version: 3:7.92-5.el9 Fixed Version: References: access.redhat.com github.com github.com nmap.org nvd.nist.gov www.cve.org www.vulncheck.com |
|
| MEDIUM |
CVE-2026-22185: OpenLDAP: OpenLDAP LMDB: Denial of Service and Information Disclosure via Heap Buffer UnderflowOpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.Package Name: openldap Installed Version: 2.6.8-4.el9 Fixed Version: References: access.redhat.com bugs.openldap.org nvd.nist.gov seclists.org seclists.org www.cve.org www.openldap.org www.vulncheck.com |
|
| MEDIUM |
CVE-2026-2673: openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement groupIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported. As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction). OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers. The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included. The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security. Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group. The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary. OpenSSL 3.6 and 3.5 are vulnerable to this issue. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released. OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.Package Name: openssl Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: www.openwall.com access.redhat.com cert-portal.siemens.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-2673: openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement groupIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported. As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction). OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers. The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included. The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security. Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group. The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary. OpenSSL 3.6 and 3.5 are vulnerable to this issue. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released. OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.Package Name: openssl-fips-provider Installed Version: 3.0.7-11.el9_8 Fixed Version: References: www.openwall.com access.redhat.com cert-portal.siemens.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-2673: openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement groupIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported. As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction). OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers. The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included. The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security. Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group. The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary. OpenSSL 3.6 and 3.5 are vulnerable to this issue. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released. OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.Package Name: openssl-fips-provider-so Installed Version: 3.0.7-11.el9_8 Fixed Version: References: www.openwall.com access.redhat.com cert-portal.siemens.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-2673: openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement groupIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported. As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction). OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers. The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included. The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security. Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group. The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary. OpenSSL 3.6 and 3.5 are vulnerable to this issue. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released. OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.Package Name: openssl-libs Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: www.openwall.com access.redhat.com cert-portal.siemens.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-13757: p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsingA flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.Package Name: p11-kit Installed Version: 0.26.2-1.el9 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-13757: p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsingA flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.Package Name: p11-kit-trust Installed Version: 0.26.2-1.el9 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-12610: sssd: Use-after-free crash in SSSD' 'sssd_pam' processA flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.Package Name: pam Installed Version: 1.5.1-28.el9 Fixed Version: References: access.redhat.com bugzilla.redhat.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-54411: linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb moduleLinux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.Package Name: pam Installed Version: 1.5.1-28.el9 Fixed Version: References: access.redhat.com cwe.mitre.org github.com github.com github.com nvd.nist.gov ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-5958: sed: GNU sed TOCTOU race conditionWhen sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: 1. resolves symlink to its target and stores the resolved path for determining when output is written, 2. opens the original symlink path (not the resolved one) to read the file. Between these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1. This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process. This issue was fixed in version 4.10.Package Name: sed Installed Version: 4.8-10.el9 Fixed Version: References: www.openwall.com access.redhat.com cert.pl github.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org www.gnu.org www.gnu.org |
|
| LOW |
CVE-2024-11053: curl: curl netrc password leakWhen asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com curl.se curl.se cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com hackerone.com linux.oracle.com linux.oracle.com nvd.nist.gov security.netapp.com security.netapp.com security.netapp.com security.netapp.com security.netapp.com security.netapp.com ubuntu.com ubuntu.com www.cve.org www.oracle.com |
|
| LOW |
CVE-2024-7264: curl: libcurl: ASN.1 date parser overreadlibcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com curl.se curl.se cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com hackerone.com linux.oracle.com linux.oracle.com nvd.nist.gov security.netapp.com security.netapp.com security.netapp.com ubuntu.com ubuntu.com www.cve.org www.oracle.com |
|
| LOW |
CVE-2024-9681: curl: HSTS subdomain overwrites parent cache entryWhen curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hosts like `x.example.com` as well as `example.com` where the first host is a subdomain of the second host. (The HSTS cache either needs to have been populated manually or there needs to have been previous HTTPS accesses done as the cache needs to have entries for the domains involved to trigger this problem.) When `x.example.com` responds with `Strict-Transport-Security:` headers, this bug can make the subdomain's expiry timeout *bleed over* and get set for the parent domain `example.com` in curl's HSTS cache. The result of a triggered bug is that HTTP accesses to `example.com` get converted to HTTPS for a different period of time than what was asked for by the origin server. If `example.com` for example stops supporting HTTPS at its expiry time, curl might then fail to access `http://example.com` until the (wrongly set) timeout expires. This bug can also expire the parent's entry *earlier*, thus making curl inadvertently switch back to insecure HTTP earlier than otherwise intended.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: seclists.org seclists.org seclists.org seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov security.netapp.com security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2025-14524: curl: Information disclosure via cross-protocol redirect with OAuth2 bearer tokenWhen an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| LOW |
CVE-2025-15079: curl: Host verification bypass during SSH transfersWhen doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2025-15224: curl: libssh key passphrase bypass without agent setWhen doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2026-6276: curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headersUsing libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.Package Name: curl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| LOW |
CVE-2024-25260: elfutils: global-buffer-overflow exists in the function ebl_machine_flag_name in eblmachineflagname.celfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.Package Name: elfutils-libelf Installed Version: 0.194-1.el9 Fixed Version: References: access.redhat.com github.com nvd.nist.gov sourceware.org sourceware.org ubuntu.com www.cve.org |
|
| LOW |
CVE-2025-1371: elfutils: GNU elfutils eu-read readelf.c handle_dynamic_symtab null pointer dereferenceA vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.Package Name: elfutils-libelf Installed Version: 0.194-1.el9 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org ubuntu.com vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org |
|
| LOW |
CVE-2025-1376: elfutils: GNU elfutils eu-strip elf_strptr.c elf_strptr denial of serviceA vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.Package Name: elfutils-libelf Installed Version: 0.194-1.el9 Fixed Version: References: access.redhat.com cert-portal.siemens.com nvd.nist.gov sourceware.org sourceware.org sourceware.org vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org |
|
| LOW |
CVE-2025-1377: elfutils: GNU elfutils eu-strip strip.c gelf_getsymshndx denial of serviceA vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.Package Name: elfutils-libelf Installed Version: 0.194-1.el9 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org ubuntu.com vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org |
|
| LOW |
CVE-2023-4156: gawk: heap out of bound read in builtin.cA heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.Package Name: gawk Installed Version: 5.1.0-6.el9 Fixed Version: References: access.redhat.com bugzilla.redhat.com git.savannah.gnu.org mail.gnu.org mail.gnu.org nvd.nist.gov ubuntu.com www.cve.org |
|
| LOW |
CVE-2024-11053: curl: curl netrc password leakWhen asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com curl.se curl.se cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com hackerone.com linux.oracle.com linux.oracle.com nvd.nist.gov security.netapp.com security.netapp.com security.netapp.com security.netapp.com security.netapp.com security.netapp.com ubuntu.com ubuntu.com www.cve.org www.oracle.com |
|
| LOW |
CVE-2024-7264: curl: libcurl: ASN.1 date parser overreadlibcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com curl.se curl.se cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com hackerone.com linux.oracle.com linux.oracle.com nvd.nist.gov security.netapp.com security.netapp.com security.netapp.com ubuntu.com ubuntu.com www.cve.org www.oracle.com |
|
| LOW |
CVE-2024-9681: curl: HSTS subdomain overwrites parent cache entryWhen curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hosts like `x.example.com` as well as `example.com` where the first host is a subdomain of the second host. (The HSTS cache either needs to have been populated manually or there needs to have been previous HTTPS accesses done as the cache needs to have entries for the domains involved to trigger this problem.) When `x.example.com` responds with `Strict-Transport-Security:` headers, this bug can make the subdomain's expiry timeout *bleed over* and get set for the parent domain `example.com` in curl's HSTS cache. The result of a triggered bug is that HTTP accesses to `example.com` get converted to HTTPS for a different period of time than what was asked for by the origin server. If `example.com` for example stops supporting HTTPS at its expiry time, curl might then fail to access `http://example.com` until the (wrongly set) timeout expires. This bug can also expire the parent's entry *earlier*, thus making curl inadvertently switch back to insecure HTTP earlier than otherwise intended.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: seclists.org seclists.org seclists.org seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov security.netapp.com security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2025-14524: curl: Information disclosure via cross-protocol redirect with OAuth2 bearer tokenWhen an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| LOW |
CVE-2025-15079: curl: Host verification bypass during SSH transfersWhen doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2025-15224: curl: libssh key passphrase bypass without agent setWhen doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2026-6276: curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headersUsing libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.Package Name: libcurl Installed Version: 7.76.1-40.el9 Fixed Version: References: www.openwall.com access.redhat.com curl.se curl.se hackerone.com nvd.nist.gov ubuntu.com www.cve.org |
|
| LOW |
CVE-2021-46195: gcc: uncontrolled recursion in libiberty/rust-demangle.cGCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.Package Name: libgcc Installed Version: 11.5.0-14.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com errata.almalinux.org gcc.gnu.org gcc.gnu.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libgcc Installed Version: 11.5.0-14.el9 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2025-11961: libpcap: libpcap: Memory corruption via malformed MAC-48 address inputpcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.Package Name: libpcap Installed Version: 14:1.10.0-4.el9 Fixed Version: References: access.redhat.com github.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2026-59846: libssh: libssh: information disclosure via ProxyCommand %r username expansionA flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.Package Name: libssh Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2026-59846: libssh: libssh: information disclosure via ProxyCommand %r username expansionA flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.Package Name: libssh-config Installed Version: 0.10.4-18.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().Package Name: ncurses-base Installed Version: 6.2-12.20210508.el9 Fixed Version: References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().Package Name: ncurses-libs Installed Version: 6.2-12.20210508.el9 Fixed Version: References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2024-13176: openssl: Timing side-channel in ECDSA signature computationIssue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network connection with low latency. For that reason the severity of this vulnerability is Low. The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.Package Name: openssl Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com github.com github.com github.com github.openssl.org github.openssl.org linux.oracle.com linux.oracle.com lists.debian.org nvd.nist.gov openssl-library.org security.netapp.com security.netapp.com security.netapp.com security.netapp.com security.netapp.com security.netapp.com ubuntu.com ubuntu.com ubuntu.com www.cve.org www.oracle.com |
|
| LOW |
CVE-2024-41996: openssl: remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculationsValidating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.Package Name: openssl Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com dheatattack.gitlab.io dheatattack.gitlab.io gist.github.com github.com nvd.nist.gov openssl-library.org www.cve.org |
|
| LOW |
CVE-2025-9232: openssl: Out-of-bounds read in HTTP client no_proxy handlingIssue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.Package Name: openssl Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: www.openwall.com access.redhat.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com github.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2026-28387: openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authenticationIssue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records. No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.Package Name: openssl Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com cert-portal.siemens.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-28388: openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processingIssue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: openssl Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com cert-portal.siemens.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-28389: openssl: OpenSSL: Denial of Service vulnerability in CMS processingIssue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: openssl Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com cert-portal.siemens.com github.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-31789: openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processingIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow. Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: openssl Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com github.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org www.openwall.com |
|
| LOW |
CVE-2024-13176: openssl: Timing side-channel in ECDSA signature computationIssue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network connection with low latency. For that reason the severity of this vulnerability is Low. The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.Package Name: openssl-libs Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com github.com github.com github.com github.openssl.org github.openssl.org linux.oracle.com linux.oracle.com lists.debian.org nvd.nist.gov openssl-library.org security.netapp.com security.netapp.com security.netapp.com security.netapp.com security.netapp.com security.netapp.com ubuntu.com ubuntu.com ubuntu.com www.cve.org www.oracle.com |
|
| LOW |
CVE-2024-41996: openssl: remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculationsValidating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.Package Name: openssl-libs Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com dheatattack.gitlab.io dheatattack.gitlab.io gist.github.com github.com nvd.nist.gov openssl-library.org www.cve.org |
|
| LOW |
CVE-2025-9232: openssl: Out-of-bounds read in HTTP client no_proxy handlingIssue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.Package Name: openssl-libs Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: www.openwall.com access.redhat.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com cert-portal.siemens.com github.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2026-28387: openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authenticationIssue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records. No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.Package Name: openssl-libs Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com cert-portal.siemens.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-28388: openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processingIssue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: openssl-libs Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com cert-portal.siemens.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-28389: openssl: OpenSSL: Denial of Service vulnerability in CMS processingIssue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: openssl-libs Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com cert-portal.siemens.com github.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-31789: openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processingIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow. Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: openssl-libs Installed Version: 1:3.5.5-6.el9_8 Fixed Version: References: access.redhat.com cert-portal.siemens.com github.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org www.openwall.com |
|
| LOW |
CVE-2022-41409: pcre2: negative repeat value in a pcre2test subject line leads to inifinite loopInteger overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.Package Name: pcre2 Installed Version: 10.40-6.el9 Fixed Version: References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2022-41409: pcre2: negative repeat value in a pcre2test subject line leads to inifinite loopInteger overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.Package Name: pcre2-syntax Installed Version: 10.40-6.el9 Fixed Version: References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2026-27171: zlib: zlib: Denial of Service via infinite loop in CRC32 combine functionszlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.Package Name: zlib Installed Version: 1.2.11-40.el9 Fixed Version: References: 7asecurity.com 7asecurity.com 7asecurity.com access.redhat.com github.com github.com github.com nvd.nist.gov ostif.org ostif.org www.cve.org |
|
| Target: | usr/local/bin/istioctl | |
| UNKNOWN |
GO-2026-5932: The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesThe golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used. If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.Package Name: golang.org/x/crypto Installed Version: v0.54.0 Fixed Version: References: go.dev pkg.go.dev |
|
Package statistics are no longer available on cloudsmith.io. Please visit our new web app to access this feature.
These instructions assume you have setup the repository first (or read it).
To pull istioctl @ reference/tag sha256:7f8809b1ca91dbf1099563c1373c4774337dc691c20805997db8bb2b9eb62244:
docker pull containers.istio.tetratelabs.com/istioctl@sha256:7f8809b1ca91dbf1099563c1373c4774337dc691c20805997db8bb2b9eb62244
You can also pull the latest version of this image (if it exists):
docker pull containers.istio.tetratelabs.com/istioctl:latest
To refer to this image after pulling in a Dockerfile, specify the following:
FROM containers.istio.tetratelabs.com/istioctl@sha256:7f8809b1ca91dbf1099563c1373c4774337dc691c20805997db8bb2b9eb62244