Known Vulnerabilities for Libyang by CESNET
Listed below are 10 of the newest known vulnerabilities associated with "Libyang" by "CESNET".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44673 json | libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integ... | Not Provided | 2026-05-14 | 2026-05-15 |
| CVE-2026-41401 json | libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates... | Not Provided | 2026-05-26 | 2026-05-26 |
| CVE-2023-26917 json | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_val... | 7.5 - HIGH | 2023-04-11 | 2023-04-18 |
| CVE-2023-26916 json | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_p... | 5.3 - MEDIUM | 2023-04-03 | 2023-11-07 |
| CVE-2021-28906 json | In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cas... | 7.5 - HIGH | 2021-05-20 | 2022-04-06 |
| CVE-2021-28905 json | In function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULL. But in some case... | 7.5 - HIGH | 2021-05-20 | 2022-04-05 |
| CVE-2021-28904 json | In function ext_get_plugin() in libyang <= v1.0.225, it doesn't check whether the value of revision is NULL. If revision is N... | 7.5 - HIGH | 2021-05-20 | 2022-04-05 |
| CVE-2021-28903 json | A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem(). lyxml_parse_elem() ... | 7.5 - HIGH | 2021-05-20 | 2022-04-05 |
| CVE-2021-28902 json | In function read_yin_container() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In som... | 7.5 - HIGH | 2021-05-20 | 2022-04-05 |
| CVE-2019-20398 json | A NULL pointer dereference is present in libyang before v1.0-r3 in the function lys_extension_instances_free() due to a copy ... | 6.5 - MEDIUM | 2020-01-22 | 2023-09-19 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cesnet | Libyang | 1.0 | |||
| Application | Cesnet | Libyang | 1.0 | |||
| Application | Cesnet | Libyang | 1.0 | |||
| Application | Cesnet | Libyang | 1.0 | |||
| Application | Cesnet | Libyang | 1.0 | |||
| Application | Cesnet | Libyang | 0.16 | |||
| Application | Cesnet | Libyang | 0.16 | |||
| Application | Cesnet | Libyang | 0.16 | |||
| Application | Cesnet | Libyang | 0.15 | |||
| Application | Cesnet | Libyang | 0.14 | |||
| Application | Cesnet | Libyang | 0.13 | |||
| Application | Cesnet | Libyang | 0.13 | |||
| Application | Cesnet | Libyang | 0.12 | |||
| Application | Cesnet | Libyang | 0.12 | |||
| Application | Cesnet | Libyang | 0.11 | |||
| Application | Cesnet | Libyang | 0.11 |