Gnu Sasl vulnerabilities
3 known vulnerabilities affecting gnu/gnu_sasl.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-2469P3HIGHCVSS 8.1fixed in 2.0.1v>=0.0.0, <2.0.12022-07-19
CVE-2022-2469 [HIGH] CWE-125 CVE-2022-2469: GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
nvd
CVE-2026-48829P3HIGHCVSS 7.5fixed in 2.2.32026-05-24
CVE-2026-48829 [HIGH] CWE-476 CVE-2026-48829: In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and serve
In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
cvelistv5nvd
CVE-2026-56968P4MEDIUMCVSS 5.3fixed in 2.2.42026-06-23
CVE-2026-56968 [MEDIUM] CWE-839 CVE-2026-56968: GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
nvd