CVE-2026-35505
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
30/06/2026
Last modified:
01/07/2026
Description
An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH


