Known Vulnerabilities for GNU SASL by GNU
Listed below are 1 of the newest known vulnerabilities associated with "GNU SASL" by "GNU".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-48829 json | In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token wit... | Not Provided | 2026-05-24 | 2026-05-26 |
| CVE-2026-47784 json | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp ... | Not Provided | 2026-05-20 | 2026-05-20 |
| CVE-2026-47783 json | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop ... | Not Provided | 2026-05-20 | 2026-05-20 |
| CVE-2026-41319 json | MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versi... | Not Provided | 2026-04-24 | 2026-04-25 |
| CVE-2026-33557 json | A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-6691 json | The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a hea... | Not Provided | 2026-05-06 | 2026-05-07 |
| CVE-2025-59032 json | ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve s... | Not Provided | 2026-03-27 | 2026-03-27 |
| CVE-2025-59028 json | When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication ... | Not Provided | 2026-03-27 | 2026-03-27 |
| CVE-2022-22576 json | An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authent... | Not Provided | 2022-05-26 | 2026-05-27 |
| CVE-2022-2469 json | GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client | 8.1 - HIGH | 2022-07-19 | 2022-10-26 |