CVE-2026-43964Low· 3.7▾ SunlitPostfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.5%
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
postfix < 3.8.16postfix >= 3.9.0, < 3.9.10postfix >= 3.10.0, < 3.10.9Upgrade past the affected range:
postfix 3.10.9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93018NoneImager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader add…
CVE-2026-76081Medium· 5.5ZITADEL is an open source identity management platform
CVE-2026-90781Medium· 4.4alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters
CVE-2026-81012Medium· 5.5kernel: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (CVE-2026-81012)
CVE-2026-89751Medium· 4.7kernel: Linux kernel (x86/tdx): Off-by-one error in port I/O handling (CVE-2026-89751)
CVE-2026-63387High· 7.0Libevent is an event notification library