[{"id":"EUVD-2026-48560","enisaUuid":"e9449b66-159f-32fd-a1f1-697afe36d974","description":"Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured allowlist or regex. This can lead to intercepting the CAS exchange, capturing the Ticket-Granting Ticket (TGT), and subsequently obtaining Service Tickets on behalf of the victim. \n\n\nBecause maintainers contact attempts were unsuccessful, vulnerabilities have only been confirmed in version 4.1.0 (Java Apereo CAS Client) and 3.6.4 (Jasig CAS Client) but may also affect other versions.","datePublished":"Jul 24, 2026, 11:29:26 AM","dateUpdated":"Jul 24, 2026, 12:33:58 PM","baseScore":7.4,"baseScoreVersion":"4.0","baseScoreVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","references":"https://cert.pl/en/posts/2026/07/CVE-2026-15243\nhttps://www.apereo.org/programs/software/cas\n","aliases":"GHSA-52jg-6vw4-42p8\nCVE-2026-15243\n","assigner":"CERT-PL","epss":0.17,"enisaIdVendor":[{"id":"e0eb6eea-a5b8-37d8-afb0-71984895a43b","vendor":{"name":"apereo"}}]},{"id":"EUVD-2026-48525","enisaUuid":"5c9298e1-0f79-37e2-94e6-5fb87018b937","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d","datePublished":"Jul 24, 2026, 7:44:54 AM","dateUpdated":"Jul 24, 2026, 12:32:14 PM","baseScore":1.8,"baseScoreVersion":"4.0","baseScoreVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","references":"https://cert.pl/en/posts/2026/07/CVE-2026-56391\nhttps://git.savannah.gnu.org/cgit/coreutils.git/\nhttps://git.savannah.gnu.org/cgit/coreutils.git/commit/?id\u003db60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d\n","aliases":"CVE-2026-56392\nGHSA-g24f-m2hx-pfgx\n","assigner":"CERT-PL","epss":0.15,"enisaIdVendor":[{"id":"57fd2123-0c58-3a76-8b51-12f9166934d1","vendor":{"name":"GNU"}}]},{"id":"EUVD-2026-48524","enisaUuid":"ccbf0dc1-0ae9-3667-8e91-1d0ca573ff1d","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.","datePublished":"Jul 24, 2026, 7:44:45 AM","dateUpdated":"Jul 24, 2026, 12:31:34 PM","baseScore":4.6,"baseScoreVersion":"4.0","baseScoreVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","references":"https://cert.pl/en/posts/2026/07/CVE-2026-56391\nhttps://git.savannah.gnu.org/cgit/coreutils.git/\nhttps://git.savannah.gnu.org/cgit/coreutils.git/commit/?id\u003dd64e35a8a4c0e4608321433e0d84d917e4e36371\n","aliases":"GHSA-7xvj-m9x7-qgxq\nCVE-2026-56391\n","assigner":"CERT-PL","epss":0.14,"enisaIdVendor":[{"id":"a959ac25-66f9-3ba4-a6d0-9cfe883840cc","vendor":{"name":"GNU"}}]},{"id":"EUVD-2026-31679","enisaUuid":"46fe18ed-35e4-33ec-ab88-343b1608eab2","description":"For untrusted certificates that contain the \"Authority Information Access - caIssuers URI\" extension, Szafir SDK will automatically download the parent CA certificate from the specified URL and will import it to its trust store as a \"nonqualified\" certificate. In such a case, Szafir SDK returns a success status code of 0 (\"Positively verified\") upon successful cryptographic verification and a certificate status of \"nonqualified\".\n\nFor other types of untrusted certificates, Szafir SDK returns a success status code of 0 (\"Positively verified\") upon successful cryptographic verification and a certificate status of \"nondetermined\".\n\nThis may lead integrating applications to incorrectly treat the digital signature as valid despite an untrusted certificate chain. This flaw enables authentication bypass and user impersonation:\n(1) in use-cases other than qualified certificate authentication, or\n(2) if the qualified certificate authentication use-case is not correctly implemented by the integrating application.\n\nThis issue was fixed in version 1.8.463.2.","datePublished":"May 25, 2026, 1:23:09 PM","dateUpdated":"Jul 23, 2026, 12:00:31 PM","baseScore":9.3,"baseScoreVersion":"4.0","baseScoreVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","references":"https://cert.pl/posts/2026/05/CVE-2026-9058\nhttps://www.elektronicznypodpis.pl/\n","aliases":"CVE-2026-9058\nGHSA-7hq7-5m7p-r2pp\n","assigner":"CERT-PL","epss":0.31,"enisaIdVendor":[{"id":"bad2d3fe-7b7c-3ff9-95ed-aacb9ffab727","vendor":{"name":"Krajowa Izba Rozliczeniowa"}}]}]