CVE-2026-5507
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without vali
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the cache and for the application to call specific session restore APIs.
MEDIUM · CVSS 4
EPSS 0.00016
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0