CVE-2026-5419
Vulnerability CVE-2026-5419 identified via SBOM analysis using Grype.
Scoring
- Severity
- LOW
- CVSS base score
- 3.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.38%
- CWE
- CWE-208
- Published
- 2026-06-01
- Last modified
- 2026-09-14
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Discovery 2
Weakness type
Related vulnerabilities
- CVE-2026-23519 — RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz
- CVE-2024-47178 — basic-auth-connect's callback uses time unsafe string comparison
- CVE-2025-53940 — Quiet uses insecure, inconsistent verification on local backend token
- CVE-2026-28464 — OpenClaw < 2026.2.12 - Timing Attack in Hooks Token Authentication
- CVE-2026-3337 — Timing Side-Channel in AES-CCM Tag Verification in AWS-LC
- CVE-2024-31074 — Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow informati
- CVE-2023-41313 — Apache Doris: Timing Attack weakness
- CVE-2023-25529 — NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker