Threats Tagged 'cve-2026-2303'
View all threats tagged with 'cve-2026-2303'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-2303'
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability (CVE-2026-84961) exists in the undici BalancedPool component used in Red Hat Hardened Images RPMs, specifically affecting versions from 7.24.1 up to 7.29.1 and 8.0.0 up to 8.10.2. The flaw allows a remote attacker to bypass TLS certificate validation when a custom function-valued connect or tls option is used, potentially enabling man-in-the-middle attacks by accepting otherwise untrusted certificates. This issue does not affect other undici components like Client, Pool, or Agent. A fix is available in versions 7.29.1 and later (7.x line) and 8.10.2 and later (8.x line). Join the discussion | GCVE Database | 09/09/2026, 13:42:29 UTC Added: 09/10/2026, 22:04:40 UTC |
The opentelemetry-collector-contrib package version 0.153.0-r2 addresses five security vulnerabilities including CVE-2026-2303. This release provides security fixes to remediate these issues. No CVSS score is available for CVE-2026-2303, and there are no known exploits in the wild at this time. Join the discussion | GCVE Database | 08/13/2026, 12:10:09 UTC Added: 08/14/2026, 16:36:57 UTC |
The external-secrets-fips package version 2.7.0-r1 addresses five security vulnerabilities including CVE-2026-2303. This release provides security fixes to mitigate these issues. No CVSS score or detailed impact information is provided. The package is part of the Alpine ecosystem. There is no indication of known exploits in the wild for these vulnerabilities. Join the discussion | GCVE Database | 08/13/2026, 12:10:09 UTC Added: 08/14/2026, 16:36:54 UTC |
0 A security update for Apptainer addresses a heap out-of-bounds read vulnerability (CVE-2026-2303) in the GSSAPI error handling of the go.mongodb.org mongo-driver dependency. This dependency has been removed in the updated version to mitigate the issue. The update also enables building of the SUID starter for SLES 15. The vulnerability is rated medium severity and a patch is available. Join the discussion | GCVE Database | 07/08/2026, 16:27:05 UTC Added: 08/14/2026, 16:36:57 UTC |
0 This update for apptainer fixes the following issues: Changes in apptainer: - Enable building of SUID starter for SLES 15 (jsc#PED-16347). * Security fix for CVE-2026-2303 (bsc#1270529): Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver. The dependency on mongo-driver has been removed with this version of apptainer. Join the discussion | GCVE Database | 07/08/2026, 16:27:05 UTC Added: 08/14/2026, 16:36:47 UTC |
0 The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer. Join the discussion | CVE Database V5 | 02/10/2026, 19:03:06 UTC Added: 02/10/2026, 19:46:20 UTC |
Showing 1 to 6 of 6 results