Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-12549

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00411
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-805

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 2 месяцев назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

CVSS3: 4.8
redhat
больше 2 лет назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

CVSS3: 4.8
debian
около 2 месяцев назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit ...

CVSS3: 4.8
github
около 2 месяцев назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

EPSS

Процентиль: 34%
0.00411
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-805