Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2026-14457

25 дней назад

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or servers...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-14457

26 дней назад

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or servers...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-14457

25 дней назад

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or server

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-14457

13 дней назад

RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate

EPSS: Низкий
debian логотип

CVE-2026-14457

25 дней назад

Issue summary: In a server or client configuration with RFC7250 Raw Pu ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6m2h-7hrp-6jw8

25 дней назад

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or ser...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4040-1

12 дней назад

Security update for openssl-3-livepatches

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4038-1

12 дней назад

Security update for openssl-3-livepatches

EPSS: Низкий
rocky логотип

RLSA-2026:67165

4 дня назад

Important: openssl security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:67154

4 дня назад

Important: openssl security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-67165-0

6 дней назад

ELSA-2026-67165-0: openssl security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-67154-0

6 дней назад

ELSA-2026-67154-0: openssl security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-500327

3 дня назад

ELSA-2026-500327: openssl security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-500326

4 дня назад

ELSA-2026-500326: openssl security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21744-1

17 дней назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4039-1

12 дней назад

Security update for openssl-3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-14457

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or servers...

CVSS3: 7.5
1%
Низкий
25 дней назад
redhat логотип
CVE-2026-14457

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or servers...

CVSS3: 7.5
1%
Низкий
26 дней назад
nvd логотип
CVE-2026-14457

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or server

CVSS3: 7.5
1%
Низкий
25 дней назад
msrc логотип
CVE-2026-14457

RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate

1%
Низкий
13 дней назад
debian логотип
CVE-2026-14457

Issue summary: In a server or client configuration with RFC7250 Raw Pu ...

CVSS3: 7.5
1%
Низкий
25 дней назад
github логотип
GHSA-6m2h-7hrp-6jw8

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or ser...

CVSS3: 7.5
1%
Низкий
25 дней назад
suse-cvrf логотип
SUSE-SU-2026:4040-1

Security update for openssl-3-livepatches

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:4038-1

Security update for openssl-3-livepatches

12 дней назад
rocky логотип
RLSA-2026:67165

Important: openssl security, bug fix, and enhancement update

4 дня назад
rocky логотип
RLSA-2026:67154

Important: openssl security, bug fix, and enhancement update

4 дня назад
oracle-oval логотип
ELSA-2026-67165-0

ELSA-2026-67165-0: openssl security, bug fix, and enhancement update (IMPORTANT)

6 дней назад
oracle-oval логотип
ELSA-2026-67154-0

ELSA-2026-67154-0: openssl security, bug fix, and enhancement update (IMPORTANT)

6 дней назад
oracle-oval логотип
ELSA-2026-500327

ELSA-2026-500327: openssl security update (IMPORTANT)

3 дня назад
oracle-oval логотип
ELSA-2026-500326

ELSA-2026-500326: openssl security update (IMPORTANT)

4 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21744-1

Security update for openssl-3

17 дней назад
suse-cvrf логотип
SUSE-SU-2026:4039-1

Security update for openssl-3

12 дней назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.