PULSE
EN VIVO14señales / 24h
FEED
ransomthegentlemen reclama a Promatrix · US · Technologyransomthegentlemen reclama a Malaysian Nuclear Agency · MY · Government & Defenseransomthegentlemen reclama a Delkart Industries Pvt · IN · Manufacturingransomthegentlemen reclama a ETA Technology Pvt · IN · Technologyransomthegentlemen reclama a Kontact Consortium India Pvt · IN · Otherransomthegentlemen reclama a Upanal CNC Solutions · PE · Manufacturingransomthegentlemen reclama a Indus Protech Solutions · IN · Technologyransomthegentlemen reclama a Angel Hotel · GB · Hospitalityransomthegentlemen reclama a The Garfield County Sheriff Office · US · Government & Defenseransommorpheus reclama a Yue Ki Industrial · TW · Manufacturingransomincransom reclama a harwal.net · AE · Not Foundransomakira reclama a Northwood Country Club · Hospitalityransomsection9 reclama a ****.com.pa · PA · Not Foundransomspacebears reclama a StellarRAD Systems · US · Technologyransomthegentlemen reclama a Promatrix · US · Technologyransomthegentlemen reclama a Malaysian Nuclear Agency · MY · Government & Defenseransomthegentlemen reclama a Delkart Industries Pvt · IN · Manufacturingransomthegentlemen reclama a ETA Technology Pvt · IN · Technologyransomthegentlemen reclama a Kontact Consortium India Pvt · IN · Otherransomthegentlemen reclama a Upanal CNC Solutions · PE · Manufacturingransomthegentlemen reclama a Indus Protech Solutions · IN · Technologyransomthegentlemen reclama a Angel Hotel · GB · Hospitalityransomthegentlemen reclama a The Garfield County Sheriff Office · US · Government & Defenseransommorpheus reclama a Yue Ki Industrial · TW · Manufacturingransomincransom reclama a harwal.net · AE · Not Foundransomakira reclama a Northwood Country Club · Hospitalityransomsection9 reclama a ****.com.pa · PA · Not Foundransomspacebears reclama a StellarRAD Systems · US · Technology
← Todos los CVEs
CVE Watch23 jul 2026

CVE-2026-13056

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing

CVSS

6.5

Medio

EPSS

0.3%

p21

KEV

Exploit Today

6

0-100

Publicado: 22 jul 2026 · Última mod.: 23 jul 2026 · CWE-1325

EPSS · 30d
0.3%EPSS · 30 días0.4%
2026-07-232026-07-28
Descripción técnica

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-54081
veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/type1/Type1FontProgram.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a crafted Type 1 font /FontDescriptor /FontFile program can execute unbounded PostScript array allocation, a zero-increment for loop, or self-recursive toExecute user dictionary lookups and exhaust validator memory, CPU, or stack. This issue is fixed in versions 1.30.2 and 1.31.23.15h
CVE-2026-54080
veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a crafted Type 0 font /Encoding or /ToUnicode CMap stream can execute unbounded PostScript array allocation or a zero-increment for loop and exhaust validator memory or CPU. This issue is fixed in versions 1.30.2 and 1.31.23.15h
CVE-2026-341837.5 ALT
60.8%
18Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service. A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.7d