在 m17n-lib 中发现了一个漏洞。通过提供包含无效 UTF-8 字符序列的构造输入,攻击者可导致文本解析函数进入无限循环。此问题会导致持续的高 CPU 占用率,从而使受影响的应用程序发生拒绝服务(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106471 | 8.1 HIGH | Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter mult |
| CVE-2026-107121 | 6.5 MEDIUM | Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downg |
| CVE-2026-103869 | 6.5 MEDIUM | Pulp-ansible: bearer tokens are reused across remotes in a worker |
| CVE-2026-103868 | 6.5 MEDIUM | Pulp-container: registry credentials are reused across remotes in a worker |
| CVE-2026-107174 | 6.4 MEDIUM | Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extr |
| CVE-2026-106064 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions |
| CVE-2026-107169 | 6.2 MEDIUM | M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8 |
| CVE-2026-107167 | 6.2 MEDIUM | M17n-lib: heap use-after-free write in re_init_ic() |
| CVE-2026-107151 | 5.9 MEDIUM | Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated request |
| CVE-2026-106061 | 5.5 MEDIUM | Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file |
| CVE-2026-103870 | 5.0 MEDIUM | Pulp-rpm: distribution tree publish creates directories from .treeinfo ids |
| CVE-2026-107170 | 2.9 LOW | M17n-lib: null dereference in minput_open_im() after failed m17n_init() |
No comments yet