HIGHVulnerability
CVE-2026-64773
An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.
Properties
- severity
- HIGH
- score
- 7.5
- epss_score
- 0.00315
- cve_id
- CVE-2026-64773
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- published_at
- 2026-08-20T22:17:48.603
- last_modified
- 2026-09-01T20:44:50.680
- epss_percentile
- 0.23963
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
AFFECTS_PRODUCT (1)
→[Product]
HAS_WEAKNESS (1)
→[Weakness]Allocation of Resources Without Limits or Throttling
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph