← Back

CVE-2026-64773

nvd nist
Published: Aug 20, 2026Modified: Sep 1, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.

Affected (1)

Products: Apple: Container
1 product
Container
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 0.3.0 to 1.2.0

References (1)

Source: product-security@apple.com
PatchVendor AdvisoryMitigation

Timeline

No history available yet.