CVE-2026-58016
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when process
CVSS
7.5
High
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Jun 30, 2026 · Last modified: Jul 21, 2026 · CWE-191
0.3%EPSS · 30 days0.4%
2026-07-012026-07-21
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:42063
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:42089
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:42090
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-58016
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2492257
- gitlab.gnome.orghttps://gitlab.gnome.org/GNOME/glib/-/issues/3932
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-442516.5 MED23.4%
——7Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the manager, immediately disconnecting all agents from the manager. A second code path reached by the same underflow may allow heap memory corruption. This issue has been fixed in version 4.14.5.2dCVE-2026-409553.7 LOW10.2%
——3CVE-2026-40955 is an integer underflow
vulnerability in the traffic parsing function of Secure Access clients prior to
14.55. Attackers with intimate knowledge of and total control over the tunnel
protocol can create a non-persistent DoS against their client.5dCVE-2026-409543.7 LOW10.2%
——3CVE-2026-40954
is an integer underflow vulnerability in the traffic parsing function of Secure
Access clients prior to 14.55. Attackers with intimate knowledge of and total
control over the tunnel protocol can create a non-persistent DoS against their
client5dCVE-2026-482986.2 MED4.9%
——1CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.5dCVE-2026-482966.2 MED5.0%
——1CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.5dCVE-2026-550397.8 HIG22.4%
——7Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.5d