Skip to main content

Threats Tagged 'cve-2026-25727'

View all threats tagged with 'cve-2026-25727'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-25727

Threats Tagged 'cve-2026-25727'

Click on any threat for detailed analysis and mitigation recommendations

0

This security update for gstreamer-devtools addresses multiple vulnerabilities across several components, including race conditions causing double-free and memory corruption, terminal manipulation via ANSI escape sequences, integer overflow leading to crashes, stack exhaustion from date parsing, process crashes from malformed HTTP headers, and information disclosure from improper folder handling. These issues affect various libraries and modules used in the SUSE product environment.

Join the discussion
0

A security update for the SUSE agama package addresses CVE-2026-25727, a vulnerability in the time crate's RFC 2822 date parser. The flaw involves parsing user-provided input which can lead to stack exhaustion, potentially causing denial of service. The update includes upgrading the time crate to version 0.3.47 to fix this issue. The vulnerability is rated as high severity. A patch is available and should be applied to affected versions.

Join the discussion
0

A security update for rust-keylime addresses a vulnerability identified as CVE-2026-25727, which involves a date parser that can lead to stack exhaustion in the Time component. This issue was fixed by updating vendored crates in version 0.2.8+116. The vulnerability is rated as high severity. No specific affected versions were provided in the available data.

Join the discussion

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cve-2026-25727
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses