CVE-2026-35091High· 8.2▾ TwilightA flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents
corosyncopenshift = 4.0enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-35092High· 7.5A flaw was found in Corosync
CVE-2026-81665High· 7.5A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly
CVE-2026-81666Medium· 6.5An integer overflow was found in Corosync's handling of membership commit token messages
CVE-2026-31503Medium· 5.5kernel: udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503)
CVE-2026-59847Medium· 5.9A flaw was found in libssh
CVE-2026-15686High· 7.2Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability