Threats Tagged 'cve-2026-54876'
View all threats tagged with 'cve-2026-54876'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-54876'
Click on any threat for detailed analysis and mitigation recommendations
0 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). Join the discussion | GCVE Database | 09/02/2026, 15:55:21 UTC Added: 08/13/2026, 17:48:02 UTC |
0 A vulnerability in OpenSSL affects the OCSP response checking mechanism used during TLS certificate verification. A malicious TLS server can send a specially crafted OCSP response that causes a memory leak in client applications with OCSP checking enabled. Repeated connections to such a server may exhaust client memory, resulting in a denial of service (DoS). This issue is tracked as CVE-2026-54876 and is addressed in Red Hat Hardened Images RPMs updates. Join the discussion | GCVE Database | 08/21/2026, 01:48:23 UTC Added: 08/05/2026, 18:46:59 UTC |
This update includes the following RPMs: ruby4.0: * ruby4.0-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-bundled-gems-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-default-gems-4.0.6-37.2.hum1 (noarch) * ruby4.0-devel-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-doc-4.0.6-37.2.hum1 (noarch) * ruby4.0-libs-4.0.6-37.2.hum1 (aarch64, x86_64) * rubygem4.0-bigdecimal-4.0.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-bundler-4.0.16-37.2.hum1 (noarch) * rubygem4.0-devel-4.0.16-37.2.hum1 (noarch) * rubygem4.0-io-console-0.8.2-37.2.hum1 (aarch64, x86_64) * rubygem4.0-irb-1.16.0-37.2.hum1 (noarch) * rubygem4.0-json-2.18.0-37.2.hum1 (aarch64, x86_64) * rubygem4.0-minitest-6.0.0-37.2.hum1 (noarch) * rubygem4.0-power_assert-3.0.1-37.2.hum1 (noarch) * rubygem4.0-psych-5.3.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-racc-1.8.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-rake-13.3.1-37.2.hum1 (noarch) * rubygem4.0-rbs-3.10.0-37.2.hum1 (aarch64, x86_64) * rubygem4.0-rdoc-7.0.4-37.2.hum1 (noarch) * rubygem4.0-rexml-3.4.4-37.2.hum1 (noarch) * rubygem4.0-rss-0.3.2-37.2.hum1 (noarch) * rubygem4.0-rubygems-4.0.16-37.2.hum1 (noarch) * rubygem4.0-test-unit-3.7.5-37.2.hum1 (noarch) * rubygem4.0-typeprof-0.31.1-37.2.hum1 (noarch) * ruby4.0-4.0.6-37.2.hum1.src (src) Security Fix(es): ruby4.0: * CVE-2026-33210 Join the discussion | GCVE Database | 08/20/2026, 14:56:34 UTC Added: 05/26/2026, 20:58:40 UTC |
This update includes the following RPMs: ruby4.0: * ruby4.0-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-bundled-gems-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-default-gems-4.0.6-37.2.hum1 (noarch) * ruby4.0-devel-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-doc-4.0.6-37.2.hum1 (noarch) * ruby4.0-libs-4.0.6-37.2.hum1 (aarch64, x86_64) * rubygem4.0-bigdecimal-4.0.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-bundler-4.0.16-37.2.hum1 (noarch) * rubygem4.0-devel-4.0.16-37.2.hum1 (noarch) * rubygem4.0-io-console-0.8.2-37.2.hum1 (aarch64, x86_64) * rubygem4.0-irb-1.16.0-37.2.hum1 (noarch) * rubygem4.0-json-2.18.0-37.2.hum1 (aarch64, x86_64) * rubygem4.0-minitest-6.0.0-37.2.hum1 (noarch) * rubygem4.0-power_assert-3.0.1-37.2.hum1 (noarch) * rubygem4.0-psych-5.3.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-racc-1.8.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-rake-13.3.1-37.2.hum1 (noarch) * rubygem4.0-rbs-3.10.0-37.2.hum1 (aarch64, x86_64) * rubygem4.0-rdoc-7.0.4-37.2.hum1 (noarch) * rubygem4.0-rexml-3.4.4-37.2.hum1 (noarch) * rubygem4.0-rss-0.3.2-37.2.hum1 (noarch) * rubygem4.0-rubygems-4.0.16-37.2.hum1 (noarch) * rubygem4.0-test-unit-3.7.5-37.2.hum1 (noarch) * rubygem4.0-typeprof-0.31.1-37.2.hum1 (noarch) * ruby4.0-4.0.6-37.2.hum1.src (src) Security Fix(es): ruby4.0: * CVE-2026-33210 Join the discussion | GCVE Database | 08/20/2026, 14:56:34 UTC Added: 05/26/2026, 20:58:31 UTC |
Showing 1 to 4 of 4 results