Beveiligingsadvies

CVE-2026-12549

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-22 13:55:06
Laatst bijgewerkt 2026-06-23 14:18:41
Toegewezen door redhat
CVSS-score 4.8
Status PUBLISHED

Beschrijving

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.