runtime_toolkit vulnerabilities
CVEs whose affected-version data names the runtime_toolkit package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-76992High· 7.5The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger…
▾ TwilightCODESYS · Development System 3via NVD
CVE-2026-79625High· 8.1Affected products do not properly synchronize access to their monitoring functionality
Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authen…
▾ TwilightCODESYS · Control RTE (SL)via NVD