CVE-2026-34477
Medium Severity
Description
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the...
Related Vulnerabilities
- CVE-2026-5264: Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1 HIGH
- CVE-2025-13926: An attacker could use data obtained by sniffing the network traffic to
forge packets in order to ma CRITICAL
- CVE-2026-33092: Local privilege escalation due to improper handling of environment variables. The following products HIGH
- CVE-2026-34944: Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64 MEDIUM
- CVE-2026-40198: Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP MEDIUM
Related Coverage
Threat Actors