VDB

CVE-2026-48829

CVE-2026-48829 PUBLISHED CVSS 7.5 HIGH

Reported by mitre · Published May 24, 2026

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

EPSS 0.46% · 38.8th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.46%
38.8th percentile

Affected Products

VendorProductVersions
GNUGNU SASL0
GNUGNU SASL0
gnugnu_sasl0

Timeline

  • May 24, 2026 EPSS Score
  • May 24, 2026 CVE Published
  • May 24, 2026 PoC Published
  • May 24, 2026 PoC Published
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
  • May 28, 2026 EPSS Score
  • May 29, 2026 EPSS Score
  • May 30, 2026 EPSS Score
  • May 31, 2026 EPSS Score
  • Jun 1, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›