๐Ÿ” CVE Alert

CVE-2026-25506

HIGH 7.7

MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.

CWE CWE-787
Vendor dun
Product munge
Published Feb 10, 2026
Last Updated Jun 30, 2026
Stay Ahead of the Next One

Get instant alerts for dun munge

Be the first to know when new high vulnerabilities affecting dun munge are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

dun / munge
>= 0.5, < 0.5.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dun/munge/security/advisories/GHSA-r9cr-jf4v-75gh github.com: https://github.com/dun/munge/commit/bf40cc27c4ce8451d4b062c9de0b67ec40894812 github.com: https://github.com/dun/munge/releases/tag/munge-0.5.18 openwall.com: http://www.openwall.com/lists/oss-security/2026/02/10/3 lists.debian.org: https://lists.debian.org/debian-lts-announce/2026/02/msg00015.html openwall.com: http://www.openwall.com/lists/oss-security/2026/02/17/6 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-25506 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2438715 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25506.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2954 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3033 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3032 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3011 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3010 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3013 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3012 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2949 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2934 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2923 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2918 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3034 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:16174