Tag
#DoS
UnrealIRCd Vulnerability: CVE-2026-90668 - Denial of Service via Unlimited HTTP Request Headers
A vulnerability in UnrealIRCd 6.0.5 through 6.2.6 allows remote attackers to cause a denial of service via an HTTP request with an unlimited number of headers. The vulnerability has a CVSS score of 7.5 and is not actively exploited. Affected versions should be updated to 6.2.7 or later.
CVE-2026-38636: relibc seekdir() Function Denial of Service Vulnerability
A vulnerability in the seekdir() function of relibc allows attackers to cause a Denial of Service (DoS) via a crafted input. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Affected systems include those using relibc commit 61f42d.
Critical Denial of Service Vulnerability in OWASP JSON Sanitizer (CVE-2026-37736)
A critical Denial of Service (DoS) vulnerability has been discovered in the OWASP JSON Sanitizer library, specifically in the `JsonSanitizer.sanitize()` component of version 1.2.3. This vulnerability, tracked as CVE-2026-37736, has a CVSS score of 7.5 and can be exploited via a crafted input. While it is not currently being actively exploited, its severity and potential impact make it a high-priority concern for organizations using this library. Immediate patching or mitigation is recommended.
Understanding the Quadratic DoS Vulnerability in sqlparse's group_comments
This educational analysis delves into the CVE-2026-71491 vulnerability in the sqlparse library, which can lead to a Denial of Service (DoS) due to a quadratic time complexity issue in the group_comments function. The goal is to provide security practitioners and technical learners with a deep understanding of the threat, its mechanics, and defensive strategies.
vm2 Buffer Alloc Limit Bypass via Buffer.concat and Buffer.from
A vulnerability in vm2 allows untrusted sandbox code to bypass the bufferAllocLimit cap, leading to a potential DoS attack. The vulnerability has a CVSS score of 8.7 and is identified as CVE-2026-47683.
CVE-2026-20339: ClamAV PESpin File Format Parser Vulnerability
A vulnerability in ClamAV's PESpin file format parser could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. The vulnerability has a CVSS score of 7.5 and is not currently being actively exploited.