Количество 2
Количество 2
CVE-2026-56401
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
GHSA-h67j-gxv6-33g4
Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolled agent can send a verifier-valid DataValue message omitting the optional id field, causing wazuh-modulesd to crash when dereferencing data->id()->string_view() without null validation, resulting in denial of service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56401 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 2 месяца назад | |||
GHSA-h67j-gxv6-33g4 Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolled agent can send a verifier-valid DataValue message omitting the optional id field, causing wazuh-modulesd to crash when dereferencing data->id()->string_view() without null validation, resulting in denial of service. | CVSS3: 6.5 | 2 месяца назад |
Уязвимостей на страницу