Medium severity6.5NVD Advisory· Published Jun 26, 2026· Updated Jun 26, 2026
CVE-2026-57914
CVE-2026-57914
Description
By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
1- Apache Software Foundation: 21 Vulnerabilities Across Multiple Products Disclosed in Early July 2026Vypr Intelligence · Jul 3, 2026