VYPR

Kerby

by Apache

CVEs (2)

  • CVE-2026-57915HigJun 26, 2026
    risk 0.47cvss 7.3epss 0.00

    It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

  • CVE-2026-57914MedJun 26, 2026
    risk 0.42cvss 6.5epss 0.00

    By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.