#denialofservice — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #denialofservice, aggregated by home.social.
-
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption
A misconfigured open directory on IP address 86.53.111[.]212:8080 exposed critical details of an active cybercrime operation, including Moobot botnet source code, denial of service tools with attack records, and a fraudulent Chinese identity verification service. The exposed directory also contained StresD Pro+, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the collection date. The recovered Moobot source code revealed a previously unknown dormant download-and-execute functionality that represents the most plausible mechanism behind APT28's repurposing of Moobot for deploying malware to compromised devices. Despite a 2024 court-authorized disruption by the U.S. Department of Justice, Moobot remains active as of August 2026, with one active C2 server observed conducting over 500 short-duration attacks throughout the month, consistent with DDoS-as-a-service operations.
Pulse ID: 6a90f19bbcdbb55af3412789
Pulse Link: https://otx.alienvault.com/pulse/6a90f19bbcdbb55af3412789
Pulse Author: AlienVault
Created: 2026-08-28 02:25:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT28 #Chinese #CyberCrime #CyberSecurity #DDoS #DenialofService #DoS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #bot #botnet #AlienVault
-
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption
A misconfigured open directory on IP address 86.53.111[.]212:8080 exposed critical details of an active cybercrime operation, including Moobot botnet source code, denial of service tools with attack records, and a fraudulent Chinese identity verification service. The exposed directory also contained StresD Pro+, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the collection date. The recovered Moobot source code revealed a previously unknown dormant download-and-execute functionality that represents the most plausible mechanism behind APT28's repurposing of Moobot for deploying malware to compromised devices. Despite a 2024 court-authorized disruption by the U.S. Department of Justice, Moobot remains active as of August 2026, with one active C2 server observed conducting over 500 short-duration attacks throughout the month, consistent with DDoS-as-a-service operations.
Pulse ID: 6a90f19bbcdbb55af3412789
Pulse Link: https://otx.alienvault.com/pulse/6a90f19bbcdbb55af3412789
Pulse Author: AlienVault
Created: 2026-08-28 02:25:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT28 #Chinese #CyberCrime #CyberSecurity #DDoS #DenialofService #DoS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #bot #botnet #AlienVault
-
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption
A misconfigured open directory on IP address 86.53.111[.]212:8080 exposed critical details of an active cybercrime operation, including Moobot botnet source code, denial of service tools with attack records, and a fraudulent Chinese identity verification service. The exposed directory also contained StresD Pro+, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the collection date. The recovered Moobot source code revealed a previously unknown dormant download-and-execute functionality that represents the most plausible mechanism behind APT28's repurposing of Moobot for deploying malware to compromised devices. Despite a 2024 court-authorized disruption by the U.S. Department of Justice, Moobot remains active as of August 2026, with one active C2 server observed conducting over 500 short-duration attacks throughout the month, consistent with DDoS-as-a-service operations.
Pulse ID: 6a90f19bbcdbb55af3412789
Pulse Link: https://otx.alienvault.com/pulse/6a90f19bbcdbb55af3412789
Pulse Author: AlienVault
Created: 2026-08-28 02:25:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT28 #Chinese #CyberCrime #CyberSecurity #DDoS #DenialofService #DoS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #bot #botnet #AlienVault
-
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption
A misconfigured open directory on IP address 86.53.111[.]212:8080 exposed critical details of an active cybercrime operation, including Moobot botnet source code, denial of service tools with attack records, and a fraudulent Chinese identity verification service. The exposed directory also contained StresD Pro+, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the collection date. The recovered Moobot source code revealed a previously unknown dormant download-and-execute functionality that represents the most plausible mechanism behind APT28's repurposing of Moobot for deploying malware to compromised devices. Despite a 2024 court-authorized disruption by the U.S. Department of Justice, Moobot remains active as of August 2026, with one active C2 server observed conducting over 500 short-duration attacks throughout the month, consistent with DDoS-as-a-service operations.
Pulse ID: 6a90f19bbcdbb55af3412789
Pulse Link: https://otx.alienvault.com/pulse/6a90f19bbcdbb55af3412789
Pulse Author: AlienVault
Created: 2026-08-28 02:25:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT28 #Chinese #CyberCrime #CyberSecurity #DDoS #DenialofService #DoS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #bot #botnet #AlienVault
-
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption
A misconfigured open directory on IP address 86.53.111[.]212:8080 exposed critical details of an active cybercrime operation, including Moobot botnet source code, denial of service tools with attack records, and a fraudulent Chinese identity verification service. The exposed directory also contained StresD Pro+, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the collection date. The recovered Moobot source code revealed a previously unknown dormant download-and-execute functionality that represents the most plausible mechanism behind APT28's repurposing of Moobot for deploying malware to compromised devices. Despite a 2024 court-authorized disruption by the U.S. Department of Justice, Moobot remains active as of August 2026, with one active C2 server observed conducting over 500 short-duration attacks throughout the month, consistent with DDoS-as-a-service operations.
Pulse ID: 6a90f19bbcdbb55af3412789
Pulse Link: https://otx.alienvault.com/pulse/6a90f19bbcdbb55af3412789
Pulse Author: AlienVault
Created: 2026-08-28 02:25:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT28 #Chinese #CyberCrime #CyberSecurity #DDoS #DenialofService #DoS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #bot #botnet #AlienVault
-
OpenSSL Updates Close Heap Corruption and Remote Crash Weaknesses
OpenSSL has released patched builds for a broad set of vulnerabilities affecting CMS, CMP, DTLS, QUIC and cryptographic operations. Several weaknesses are remotely triggerable, making dependency discovery and timely upgrades important for exposed services and embedded applications.https://securebulletin.com/openssl-updates-close-heap-corruption-and-remote-crash-weaknesses/
-
Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.
-
Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.
-
Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.
-
Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.
-
The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.
-
The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.
-
The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.
-
NVIDIA Triton vulnerability CVE-2026-47627 scores CVSS 9.8. Learn how the denial of service flaw works and why you must update to version 26.06 now.
#NVIDIA #TritonInferenceServer #CVE202647627 #DenialOfService #AIsecurity #CVSS
-
Cisco confirmed active exploitation of CVE-2026-20349, a high-severity flaw (CVSS 8.6) in ASA and FTD firewalls. Insufficient error handling in HTTP processing allows an unauthenticated remote attacker to trigger a device reboot via the Remote Access SSL VPN service, resulting in denial of service.
#CVE202620349 #CiscoASA #FirewallSecurity #DenialOfService
https://cyberworldops.eu/en/cisco-asa-and-ftd-actively-exploited-vulnerability-can-restart
-
Cisco confirmed active exploitation of CVE-2026-20349, a high-severity flaw (CVSS 8.6) in ASA and FTD firewalls. Insufficient error handling in HTTP processing allows an unauthenticated remote attacker to trigger a device reboot via the Remote Access SSL VPN service, resulting in denial of service.
#CVE202620349 #CiscoASA #FirewallSecurity #DenialOfService
https://cyberworldops.eu/en/cisco-asa-and-ftd-actively-exploited-vulnerability-can-restart
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/iHTpuX #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/iHTpuX #CVE #denialofservice #securityadvisory
-
MongoDB patched 27 vulnerabilities across Server and Compass. The set includes memory corruption, RBAC bypass, and denial-of-service flaws. Update now.
-
MongoDB patched 27 vulnerabilities across Server and Compass. The set includes memory corruption, RBAC bypass, and denial-of-service flaws. Update now.
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/iHTpuX #CVE #denialofservice #securityadvisory
-
An HTTP/2 DoS vulnerability lets unauthenticated attackers exhaust server memory via stalled flow control. CVE-2026-59762 and CVE-2026-59173 are patched.
#HTTP2 #DoS #DenialOfService #CVE202659762 #CVE202659173 #FlowControl #InfoSec #PatchNow
http://securityonline.info/http2-dos-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
-
An HTTP/2 DoS vulnerability lets unauthenticated attackers exhaust server memory via stalled flow control. CVE-2026-59762 and CVE-2026-59173 are patched.
#HTTP2 #DoS #DenialOfService #CVE202659762 #CVE202659173 #FlowControl #InfoSec #PatchNow
http://securityonline.info/http2-dos-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/iHTpuX #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/iHTpuX #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/iHTpuX #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/iHTpuX #CVE #denialofservice #securityadvisory
-
Greenfield cyberattack disrupts internet in California community #DenialOfService #InternetOutage #California #GreenfieldCommunications #RanchoMurieta #SacramentoCounty https://dysruptionhub.com/greenfield-california-internet-cyberattack/
-
Greenfield cyberattack disrupts internet in California community #DenialOfService #InternetOutage #California #GreenfieldCommunications #RanchoMurieta #SacramentoCounty https://dysruptionhub.com/greenfield-california-internet-cyberattack/
-
DOS by CloudFlare
People pay for this. I find it an odd choice of disposing of money, but good for them.
-
DOS by CloudFlare
People pay for this. I find it an odd choice of disposing of money, but good for them.
-
DOS by CloudFlare
People pay for this. I find it an odd choice of disposing of money, but good for them.
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
Am I a target?
I keep getting traffic from the same server. It's a Hetzner Online server (supposedly) which has geodata linking it to the UAE. I've blocked the traffic, but I'm getting hella suspicious. Anyway I've been live monitoring all my traffic and I'm blocking anything that I think is even the tiniest bit sus.I'm not really thrilled to be blocking a hetzner IP, since there's so many mastodon servers hosted on hetzner IPs, but like if y'all can't fucking behave you're not welcome at the party. Love […] -
Am I a target?
I keep getting traffic from the same server. It's a Hetzner Online server (supposedly) which has geodata linking it to the UAE. I've blocked the traffic, but I'm getting hella suspicious. Anyway I've been live monitoring all my traffic and I'm blocking anything that I think is even the tiniest bit sus.I'm not really thrilled to be blocking a hetzner IP, since there's so many mastodon servers hosted on hetzner IPs, but like if y'all can't fucking behave you're not welcome at the party. Love […] -
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
Nine Apache ActiveMQ vulnerabilities allow denial of service and a temporary destination takeover (CVE-2026-54475). Upgrade to 6.2.7 now.
#ApacheActiveMQ #ActiveMQ #CVE202654475 #DenialOfService #OpenWire #STOMP #MessageBroker #Vulnerability
-
Nine Apache ActiveMQ vulnerabilities allow denial of service and a temporary destination takeover (CVE-2026-54475). Upgrade to 6.2.7 now.
#ApacheActiveMQ #ActiveMQ #CVE202654475 #DenialOfService #OpenWire #STOMP #MessageBroker #Vulnerability
-
Six NetScaler vulnerabilities allow denial of service, memory overreads, and an unauthenticated file read. Patch NetScaler ADC and Gateway now.
#NetScaler #NetScalerADC #NetScalerGateway #Citrix #CVE20268451 #DenialOfService #Vulnerability
-
Six NetScaler vulnerabilities allow denial of service, memory overreads, and an unauthenticated file read. Patch NetScaler ADC and Gateway now.
#NetScaler #NetScalerADC #NetScalerGateway #Citrix #CVE20268451 #DenialOfService #Vulnerability
-
Six NetScaler vulnerabilities allow denial of service, memory overreads, and an unauthenticated file read. Patch NetScaler ADC and Gateway now.
#NetScaler #NetScalerADC #NetScalerGateway #Citrix #CVE20268451 #DenialOfService #Vulnerability
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
CISA Flags SolarWinds Serv-U Flaw as Actively Exploited
A critical flaw in SolarWinds Serv-U is being actively exploited, allowing attackers to crash the service with a specially crafted POST request - no authentication required. This denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered by a simple HTTP POST request with a malicious Content-Encoding header.
#Solarwinds #Servu #Cve202628318 #DenialOfService #Contentencoding
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
Hackers Actively Exploit SolarWinds Serv-U Flaw to Crash Servers
SolarWinds has issued an emergency hotfix to address a critical flaw in its Serv-U file transfer product, which hackers are actively exploiting to crash servers with specially crafted POST requests. A denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered without authentication, posing a significant threat to…
#Cve202628318 #Solarwinds #Servu #DenialOfService #ManagedFileTransfer
-
Codex Agent Uncovers Lethal HTTP/2 DoS Exploit
A home computer on a typical 100Mbps connection can cripple a vulnerable server in mere seconds with the HTTP/2 Bomb, a potent DoS exploit that combines two decade-old attack techniques. This devastating attack exhausts server memory by sending tiny, compressed HTTP/2 header fragments and holding connections open, taking the service offline.
#Http2DosExploit #DenialOfService #Hpack #Slowloris #Cve20166581
-
Codex Agent Uncovers Lethal HTTP/2 DoS Exploit
A home computer on a typical 100Mbps connection can cripple a vulnerable server in mere seconds with the HTTP/2 Bomb, a potent DoS exploit that combines two decade-old attack techniques. This devastating attack exhausts server memory by sending tiny, compressed HTTP/2 header fragments and holding connections open, taking the service offline.
#Http2DosExploit #DenialOfService #Hpack #Slowloris #Cve20166581
-
HTTP/2 Bomb Attack Disrupts Web Servers in Seconds
A home computer on a typical 100Mbps connection can cripple a vulnerable server in mere seconds using a new technique called the HTTP/2 Bomb, which cleverly combines two known weaknesses in HTTP/2 server configurations. This potent attack can be unleashed quickly, leaving servers inaccessible.
-
HTTP/2 Bomb Vulnerability Targets Major Web Servers with Remote DoS Exploit
A newly discovered HTTP/2 Bomb vulnerability can be exploited to launch a remote Denial of Service (DoS) attack on major web servers, taking advantage of a weakness in the default HTTP/2 configuration. This flaw cleverly combines a compression bomb and a Slowloris-style hold to target HPACK, HTTP/2's header-compression…
#Http2Bomb #DenialOfService #RemoteExploit #Vulnerability #WebServers
-
[ Blog ] VMware #vCenter vulnerability CVE-2025-41241
A denial of service vulnerability, identified as CVE-2025-41241, has been discovered within VMware vCenter.
Broadcom has evaluated this issue as having a moderate severity rating, with a CVSSv3 base score of 4.4. While this isn't a high-severity critical flaw, it's still an issue that could lead http://rviv.ly/GqTV8p #CVE #denialofservice #securityadvisory
-
GNU SASL <2.2.3 is vulnerable (CVE-2026-48829): HIGH severity NULL pointer dereference in DIGEST-MD5 can crash clients/servers (DoS risk). No patch yet — consider disabling DIGEST-MD5 for now. https://radar.offseq.com/threat/cve-2026-48829-cwe-476-null-pointer-dereference-in-e31bf97e #OffSeq #GNU #Vuln #DenialOfService
-
GNU SASL <2.2.3 is vulnerable (CVE-2026-48829): HIGH severity NULL pointer dereference in DIGEST-MD5 can crash clients/servers (DoS risk). No patch yet — consider disabling DIGEST-MD5 for now. https://radar.offseq.com/threat/cve-2026-48829-cwe-476-null-pointer-dereference-in-e31bf97e #OffSeq #GNU #Vuln #DenialOfService