CVE-2026-14316

The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.

  • Published Oct 1, 2026
  • CVSS 8.1 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-14316 at the National Vulnerability Database