Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7gwx-vgp2-4hmg

Опубликовано: 22 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

EPSS

Процентиль: 34%
0.00411
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-805

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 2 месяцев назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

CVSS3: 4.8
redhat
больше 2 лет назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

CVSS3: 4.8
nvd
около 2 месяцев назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

CVSS3: 4.8
debian
около 2 месяцев назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit ...

EPSS

Процентиль: 34%
0.00411
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-805