OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-14316

HIGH · CVSS 8.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A vulnerability exists in the handling of revoked-key error paths, where a heap buffer overflow occurs due to insufficient allocation size for the formatted error message generated by sprintf(). This flaw can lead to potential arbitrary code execution or denial of service, making it critical for organizations using affected products to prioritize remediation. Security teams should assess their systems for this vulnerability to mitigate risks associated with exploitation.

CVE
CVE-2026-14316
Severity
HIGH
CVSS
8.1
EPSS
0.22%

Original NVD Description

The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.