VYPR

Product Security

by Fortra

CVEs (1)

  • CVE-2026-14316HigOct 1, 2026
    risk 0.53cvss 8.1epss —

    The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.