在 sequoia-openpgp 库中发现了一个漏洞。当旧版证书中缺少密钥标志子包(key flags subpacket)时,该库会错误地推断密钥标志,导致对密钥能力的理解出现偏差。这种密钥标志的混淆使得攻击者能够绕过回签(back-signature)检查。因此,攻击者可以非法地将任意子密钥绑定到自己的证书上,并伪造签名,从而彻底破坏密码学完整性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Confidential Compute Attestation | - |
cpe:/a:redhat:confidential_compute_attestation:1
|
|
| Red Hat | Confidential Compute Attestation | - |
cpe:/a:redhat:confidential_compute_attestation:1
|
|
| Red Hat | Confidential Compute Attestation | - |
cpe:/a:redhat:confidential_compute_attestation:1
|
|
| Red Hat | Confidential Compute Attestation | - |
cpe:/a:redhat:confidential_compute_attestation:1
|
|
| Red Hat | Confidential Compute Attestation | - |
cpe:/a:redhat:confidential_compute_attestation:1
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| Red Hat | Red Hat Trusted Profile Analyzer | - |
cpe:/a:redhat:trusted_profile_analyzer:2
|
|
| Red Hat | Red Hat Trusted Profile Analyzer | - |
cpe:/a:redhat:trusted_profile_analyzer:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74909 | 8.1 HIGH | Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enfo |
| CVE-2026-79651 | 7.5 HIGH | Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching |
| CVE-2026-18212 | 7.5 HIGH | Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state |
| CVE-2026-17526 | 7.2 HIGH | Keycloak-services: keycloak-services: privilege escalation via impersonation role allows t |
| CVE-2026-92615 | 6.6 MEDIUM | Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tena |
| CVE-2026-92358 | 6.4 MEDIUM | Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil |
| CVE-2026-92091 | 5.9 MEDIUM | Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops |
| CVE-2026-19607 | 5.3 MEDIUM | Keycloak-services: keycloak-services: broker-originated username collision causes account |
No comments yet