Low severity3.7NVD Advisory· Published May 4, 2026· Updated May 11, 2026
CVE-2026-43964
CVE-2026-43964
Description
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.openwall.com/lists/oss-security/2026/05/04/30nvdMailing ListThird Party Advisory
- www.mail-archive.com/postfix-announce@postfix.org/msg00110.htmlnvdMailing ListThird Party Advisory
News mentions
1- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026