Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-57914EXPLOITEDPATCHED
apache · kerby

Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures

Description

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

Affected Products

VendorProductVersions
apachekerby0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibminfosphere informationcert_advisory90%

References

  • https://lists.apache.org/thread/w98h2q8wz0bq97vhz4vf55hqomcb2j1m(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories6h ago
[NEU] [hoch] IBM InfoSphere Information Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security47d ago
CVE-2026-57914: Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
→ No new info (linked only)
Tier C
VulDB47d ago
CVE-2026-57914 | Apache Kerby up to 2.1.1 ASN1 Structure Parser resource consumption
→ No new info (linked only)
CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2.1.2
CWECWE-400
PublishedJun 26, 2026
Last enriched47d agov3
Trending Score56
Source articles3
Independent3
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-49975EXP
Apache HTTP Server: mod_http2 denial of service
Trending: 87
HIGHCVE-2026-57915
Apache Kerby: Kerberos Pre-Authentication Bypass
Trending: 51
CRITICALCVE-2026-34191
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Trending: 43
HIGHCVE-2026-55969
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Trending: 42
HIGHCVE-2025-49506
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Trending: 37

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Updated: description, severity, affectedVersions, activelyExploited
Jun 26, 2026
Updated: affectedVersions, exploitAvailable
Jun 26, 2026
Actively Exploited
Jun 26, 2026
Exploit Available
Jun 26, 2026
Patch Available
Jun 26, 2026

Version History

v3
Last enriched 47d ago
v3Tier C47d ago

Updated severity to MEDIUM, added affected versions before 2.1.2, marked exploit as available.

affectedVersionsexploitAvailable
via oss-security
v2Tier C47d ago

Updated description with new details, changed severity to HIGH, added affected version 2.1.1, and noted that no exploit is available.

descriptionseverityaffectedVersionsactivelyExploited
via VulDB
v147d ago

Initial creation