← All CVEs

CVE-2026-23556

critical · 9.4

When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota.

9.4
CVSS
0.1%
EPSS (exploit prob.)
3rd
EPSS percentile
2026-07-09
Published

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-281

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-23556