Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-48829

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published May 24, 2026
Vendor unknown

Description

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

References