VYPR
Low severity3.7NVD Advisory· Published May 4, 2026· Updated May 11, 2026

CVE-2026-43964

CVE-2026-43964

Description

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

Affected products

1
  • cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
    Range: <3.8.16

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

1