Search
Find a vulnerability
Search criteria
4 vulnerabilities by PyPy
CVE-2026-76875 (GCVE-0-2026-76875)
Vulnerability from nvd – Published: 2026-09-29 12:45 – Updated: 2026-10-02 12:07 X_Open Source
VLAI
EPSS
VEX
Title
PyPy pyexpat ExternalEntityParserCreate Use-After-Free
Summary
PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 12:07 UTC
CWE
- CWE-416 - Use After Free
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://doc.pypy.org/release-v8.0.0.html | release-notes |
| https://github.com/pypy/pypy/releases/tag/release… | patch |
| https://github.com/pypy/pypy/releases/tag/release… | patch |
| https://www.vulncheck.com/advisories/pypy-pyexpat… | third-party-advisory |
Impacted products
Date Public
2026-09-19 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76875",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T12:07:14.237053Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T12:07:30.652Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/pypy/pypy",
"product": "PyPy",
"repo": "https://github.com/pypy/pypy",
"vendor": "PyPy",
"versions": [
{
"lessThan": "3.11.16",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "3.12.14",
"status": "affected",
"version": "3.12.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Fabian Wahle (Hap Security)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulnCheck"
}
],
"datePublic": "2026-09-19T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module\u0027s ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy\u0027s tracing garbage collector can free the parent\u0027s C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-416",
"description": "Use After Free",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T12:45:19.797Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Release Notes",
"tags": [
"release-notes"
],
"url": "https://doc.pypy.org/release-v8.0.0.html"
},
{
"name": "3.12 Release Tag",
"tags": [
"patch"
],
"url": "https://github.com/pypy/pypy/releases/tag/release-pypy3.12-v8.0.0"
},
{
"name": "3.11 Release Tag",
"tags": [
"patch"
],
"url": "https://github.com/pypy/pypy/releases/tag/release-pypy3.11-v8.0.0"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/pypy-pyexpat-externalentityparsercreate-use-after-free"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source"
],
"title": "PyPy pyexpat ExternalEntityParserCreate Use-After-Free",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-76875",
"datePublished": "2026-09-29T12:45:19.797Z",
"dateReserved": "2026-08-19T21:47:08.936Z",
"dateUpdated": "2026-10-02T12:07:30.652Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2022-37454 (GCVE-0-2022-37454)
Vulnerability from nvd – Published: 2022-10-21 00:00 – Updated: 2025-05-08 15:03
VLAI
EPSS
VEX
Summary
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
Severity
9.8 (Critical)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-05-08 15:03 UTC
CWE
- n/a
- CWE-190 - Integer Overflow or Wraparound
Assigner
References
14 references
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T10:29:21.027Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://security.netapp.com/advisory/ntap-20230203-0001/"
},
{
"name": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
"tags": [
"x_transferred"
],
"url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
},
{
"name": "https://mouha.be/sha-3-buffer-overflow/",
"tags": [
"x_transferred"
],
"url": "https://mouha.be/sha-3-buffer-overflow/"
},
{
"name": "https://news.ycombinator.com/item?id=33281106",
"tags": [
"x_transferred"
],
"url": "https://news.ycombinator.com/item?id=33281106"
},
{
"name": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
"tags": [
"x_transferred"
],
"url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
},
{
"name": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
"tags": [
"x_transferred"
],
"url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
},
{
"name": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
"tags": [
"x_transferred"
],
"url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
},
{
"name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
"tags": [
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
},
{
"name": "https://www.debian.org/security/2022/dsa-5267",
"tags": [
"x_transferred"
],
"url": "https://www.debian.org/security/2022/dsa-5267"
},
{
"name": "https://www.debian.org/security/2022/dsa-5269",
"tags": [
"x_transferred"
],
"url": "https://www.debian.org/security/2022/dsa-5269"
},
{
"name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
"tags": [
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
},
{
"tags": [
"x_transferred"
],
"url": "https://eprint.iacr.org/2023/331"
},
{
"tags": [
"x_transferred"
],
"url": "https://news.ycombinator.com/item?id=35050307"
},
{
"tags": [
"x_transferred"
],
"url": "https://security.gentoo.org/glsa/202305-02"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-37454",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-05-08T15:03:12.969240Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "CWE-190 Integer Overflow or Wraparound",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-05-08T15:03:28.946Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "unknown",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-05-03T10:06:29.726Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
"url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
},
{
"name": "https://mouha.be/sha-3-buffer-overflow/",
"url": "https://mouha.be/sha-3-buffer-overflow/"
},
{
"name": "https://news.ycombinator.com/item?id=33281106",
"url": "https://news.ycombinator.com/item?id=33281106"
},
{
"name": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
"url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
},
{
"name": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
"url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
},
{
"name": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
"url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
},
{
"name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
},
{
"name": "https://www.debian.org/security/2022/dsa-5267",
"url": "https://www.debian.org/security/2022/dsa-5267"
},
{
"name": "https://www.debian.org/security/2022/dsa-5269",
"url": "https://www.debian.org/security/2022/dsa-5269"
},
{
"name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
},
{
"url": "https://eprint.iacr.org/2023/331"
},
{
"url": "https://news.ycombinator.com/item?id=35050307"
},
{
"url": "https://security.gentoo.org/glsa/202305-02"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-37454",
"datePublished": "2022-10-21T00:00:00.000Z",
"dateReserved": "2022-08-07T00:00:00.000Z",
"dateUpdated": "2025-05-08T15:03:28.946Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2026-76875 (GCVE-0-2026-76875)
Vulnerability from cvelistv5 – Published: 2026-09-29 12:45 – Updated: 2026-10-02 12:07 X_Open Source
VLAI
EPSS
VEX
Title
PyPy pyexpat ExternalEntityParserCreate Use-After-Free
Summary
PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 12:07 UTC
CWE
- CWE-416 - Use After Free
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://doc.pypy.org/release-v8.0.0.html | release-notes |
| https://github.com/pypy/pypy/releases/tag/release… | patch |
| https://github.com/pypy/pypy/releases/tag/release… | patch |
| https://www.vulncheck.com/advisories/pypy-pyexpat… | third-party-advisory |
Impacted products
Date Public
2026-09-19 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76875",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T12:07:14.237053Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T12:07:30.652Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/pypy/pypy",
"product": "PyPy",
"repo": "https://github.com/pypy/pypy",
"vendor": "PyPy",
"versions": [
{
"lessThan": "3.11.16",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "3.12.14",
"status": "affected",
"version": "3.12.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Fabian Wahle (Hap Security)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulnCheck"
}
],
"datePublic": "2026-09-19T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module\u0027s ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy\u0027s tracing garbage collector can free the parent\u0027s C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-416",
"description": "Use After Free",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T12:45:19.797Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Release Notes",
"tags": [
"release-notes"
],
"url": "https://doc.pypy.org/release-v8.0.0.html"
},
{
"name": "3.12 Release Tag",
"tags": [
"patch"
],
"url": "https://github.com/pypy/pypy/releases/tag/release-pypy3.12-v8.0.0"
},
{
"name": "3.11 Release Tag",
"tags": [
"patch"
],
"url": "https://github.com/pypy/pypy/releases/tag/release-pypy3.11-v8.0.0"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/pypy-pyexpat-externalentityparsercreate-use-after-free"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source"
],
"title": "PyPy pyexpat ExternalEntityParserCreate Use-After-Free",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-76875",
"datePublished": "2026-09-29T12:45:19.797Z",
"dateReserved": "2026-08-19T21:47:08.936Z",
"dateUpdated": "2026-10-02T12:07:30.652Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2022-37454 (GCVE-0-2022-37454)
Vulnerability from cvelistv5 – Published: 2022-10-21 00:00 – Updated: 2025-05-08 15:03
VLAI
EPSS
VEX
Summary
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
Severity
9.8 (Critical)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-05-08 15:03 UTC
CWE
- n/a
- CWE-190 - Integer Overflow or Wraparound
Assigner
References
14 references
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T10:29:21.027Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://security.netapp.com/advisory/ntap-20230203-0001/"
},
{
"name": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
"tags": [
"x_transferred"
],
"url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
},
{
"name": "https://mouha.be/sha-3-buffer-overflow/",
"tags": [
"x_transferred"
],
"url": "https://mouha.be/sha-3-buffer-overflow/"
},
{
"name": "https://news.ycombinator.com/item?id=33281106",
"tags": [
"x_transferred"
],
"url": "https://news.ycombinator.com/item?id=33281106"
},
{
"name": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
"tags": [
"x_transferred"
],
"url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
},
{
"name": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
"tags": [
"x_transferred"
],
"url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
},
{
"name": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
"tags": [
"x_transferred"
],
"url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
},
{
"name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
"tags": [
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
},
{
"name": "https://www.debian.org/security/2022/dsa-5267",
"tags": [
"x_transferred"
],
"url": "https://www.debian.org/security/2022/dsa-5267"
},
{
"name": "https://www.debian.org/security/2022/dsa-5269",
"tags": [
"x_transferred"
],
"url": "https://www.debian.org/security/2022/dsa-5269"
},
{
"name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
"tags": [
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
},
{
"tags": [
"x_transferred"
],
"url": "https://eprint.iacr.org/2023/331"
},
{
"tags": [
"x_transferred"
],
"url": "https://news.ycombinator.com/item?id=35050307"
},
{
"tags": [
"x_transferred"
],
"url": "https://security.gentoo.org/glsa/202305-02"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-37454",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-05-08T15:03:12.969240Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "CWE-190 Integer Overflow or Wraparound",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-05-08T15:03:28.946Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "unknown",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-05-03T10:06:29.726Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
"url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
},
{
"name": "https://mouha.be/sha-3-buffer-overflow/",
"url": "https://mouha.be/sha-3-buffer-overflow/"
},
{
"name": "https://news.ycombinator.com/item?id=33281106",
"url": "https://news.ycombinator.com/item?id=33281106"
},
{
"name": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
"url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
},
{
"name": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
"url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
},
{
"name": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
"url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
},
{
"name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
},
{
"name": "https://www.debian.org/security/2022/dsa-5267",
"url": "https://www.debian.org/security/2022/dsa-5267"
},
{
"name": "https://www.debian.org/security/2022/dsa-5269",
"url": "https://www.debian.org/security/2022/dsa-5269"
},
{
"name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
},
{
"url": "https://eprint.iacr.org/2023/331"
},
{
"url": "https://news.ycombinator.com/item?id=35050307"
},
{
"url": "https://security.gentoo.org/glsa/202305-02"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-37454",
"datePublished": "2022-10-21T00:00:00.000Z",
"dateReserved": "2022-08-07T00:00:00.000Z",
"dateUpdated": "2025-05-08T15:03:28.946Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}