Skip to main content

Threats Tagged 'cve-2026-2303'

View all threats tagged with 'cve-2026-2303'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-2303

Threats Tagged 'cve-2026-2303'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability (CVE-2026-84961) exists in the undici BalancedPool component used in Red Hat Hardened Images RPMs, specifically affecting versions from 7.24.1 up to 7.29.1 and 8.0.0 up to 8.10.2. The flaw allows a remote attacker to bypass TLS certificate validation when a custom function-valued connect or tls option is used, potentially enabling man-in-the-middle attacks by accepting otherwise untrusted certificates. This issue does not affect other undici components like Client, Pool, or Agent. A fix is available in versions 7.29.1 and later (7.x line) and 8.10.2 and later (8.x line).

Join the discussion

The opentelemetry-collector-contrib package version 0.153.0-r2 addresses five security vulnerabilities including CVE-2026-2303. This release provides security fixes to remediate these issues. No CVSS score is available for CVE-2026-2303, and there are no known exploits in the wild at this time.

Join the discussion

The external-secrets-fips package version 2.7.0-r1 addresses five security vulnerabilities including CVE-2026-2303. This release provides security fixes to mitigate these issues. No CVSS score or detailed impact information is provided. The package is part of the Alpine ecosystem. There is no indication of known exploits in the wild for these vulnerabilities.

Join the discussion
0

A security update for Apptainer addresses a heap out-of-bounds read vulnerability (CVE-2026-2303) in the GSSAPI error handling of the go.mongodb.org mongo-driver dependency. This dependency has been removed in the updated version to mitigate the issue. The update also enables building of the SUID starter for SLES 15. The vulnerability is rated medium severity and a patch is available.

Join the discussion
0

This update for apptainer fixes the following issues: Changes in apptainer: - Enable building of SUID starter for SLES 15 (jsc#PED-16347). * Security fix for CVE-2026-2303 (bsc#1270529): Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver. The dependency on mongo-driver has been removed with this version of apptainer.

Join the discussion

The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cve-2026-2303
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses