CVE-2026-57914
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Description
By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-400
Source
NVD
Vendor
Apache Software Foundation
Product
Apache Kerby
Discussion (0)
Add Comment
No comments yet. Be the first!