CVE-2026-56968
PoC —CVSS 3.1
5.3 medium
EPSS
<1%p21
Published
()
Modified
Description
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
In the news0 stories
No ingested article mentions this CVE yet.