CVE-2026-5507
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-502
Deserialización de datos no confiables
Fecha de publicación:
09/04/2026
Última modificación:
09/04/2026
Descripción
*** Pendiente de traducción *** When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the cache and for the application to call specific session restore APIs.
Impacto
Puntuación base 4.0
4.10
Gravedad 4.0
MEDIA



