SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-16254

MEDIUM · CVSS 4.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

A vulnerability in claircore's apk package scanner allows for out-of-bounds access due to malformed package-database data in a container layer, potentially causing the scanner to panic. If the panic is not handled, it can result in the crash of the Clair indexer process, leading to a denial of service. Organizations utilizing claircore for container security should prioritize addressing this issue to maintain service availability.

CVE
CVE-2026-16254
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%

Original NVD Description

A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.