问题摘要:在启用了 RFC7250 原始公钥(Raw Public Keys, RPKs)的服务器或客户端配置中,如果本地仅配置了私钥(而未配置关联的证书),当远程对等方请求使用原始公钥,并同时发送通常会被省略的 "signature_algorithms_cert" TLS 扩展时,可能发生空指针解引用漏洞。 影响摘要:该漏洞的影响仅限于可能导致的应用程序中止从而引发的拒绝服务(DoS)攻击;不可能发生数据泄露或远程命令执行。 CWE:CWE-476:空指针解引用 描述:文档中的示例代码中有一段注释表明,仅使用密
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75803 | AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() | |
| CVE-2026-18798 | QUIC Server May Trigger Double Free When Processing INITIAL Packet | |
| CVE-2026-54874 | Excessive Memory Use Buffering DTLS Records for a Future Epoch | |
| CVE-2026-63074 | CMP Indefinite Cache Growth of ExtraCerts | |
| CVE-2026-63072 | Heap Buffer Overflow in CMS Key Unwrapping | |
| CVE-2026-63073 | Untrusted Sender DN Used as Format String in CMP Response Validation | |
| CVE-2026-63075 | QUIC ACK-only Packet Retention Can Cause Memory Exhaustion | |
| CVE-2026-63076 | Invalid Pointer Dereference in CMP Server via Crafted protectionAlg |
No comments yet