Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-91768

8 дней назад

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-91768

8 дней назад

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-91768

8 дней назад

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-91768

4 дня назад

IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-91768

8 дней назад

The IPv6 branch of the FastCGI client access check compares only the f ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-62xp-839h-2637

9 дней назад

IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-91768

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.

CVSS3: 6.5
1%
Низкий
8 дней назад
redhat логотип
CVE-2026-91768

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.

CVSS3: 6.5
1%
Низкий
8 дней назад
nvd логотип
CVE-2026-91768

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.

CVSS3: 6.5
1%
Низкий
8 дней назад
msrc логотип
CVE-2026-91768

IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)

CVSS3: 6.5
1%
Низкий
4 дня назад
debian логотип
CVE-2026-91768

The IPv6 branch of the FastCGI client access check compares only the f ...

CVSS3: 6.5
1%
Низкий
8 дней назад
github логотип
GHSA-62xp-839h-2637

IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)

CVSS3: 6.5
1%
Низкий
9 дней назад

Уязвимостей на страницу