CVE-2026-48829
GNU GNU SASL
In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
- CVSS
- 7.5
- EPSS
- 0.46% 37.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.24