CVE-2026-102010High· 7.0▾ TwilightA flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-4039Medium· 4.8**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being d…
CVE-2026-97023High· 7.1A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed o…
CVE-2026-96740Medium· 6.5A flaw was found in the StreamsHub Console for Apache Kafka
CVE-2026-87114High· 7.1A flaw was found in kube-compare
CVE-2026-101333Low· 3.7A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management
CVE-2026-86330High· 7.2An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api