GHSA-v7jp-vmx6-5429 · Severity: high — libyang before 5.2.6 contains a heap use-after-free write vulnerability in...
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
Conclusion & alert: CVE-2026-41401 is rated Moderate Risk (42.8/100): CVSS High severity, with low exploitation likelihood (EPSS 0.52%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.03% | 0.52% | +0.49% |
| 2 | 2026-05-27 | — | 0.03% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.1 | 4.0 | HIGH |
|
— | — | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
GHSA-v7jp-vmx6-5429 · Severity: high — libyang before 5.2.6 contains a heap use-after-free write vulnerability in...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-41401 not yet assigned priority: Debian including 2 source packages (libyang, libyang2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. | https://security-tracker.debian.org/tracker/CVE-2026-41401 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2026-41401/ |
ubuntu
|
medium | CVE-2026-41401 medium priority: Ubuntu including 2 source packages (libyang, libyang2), 11 status rows across 6 suites (focal, jammy, noble, questing, resolute, upstream): needs-triage 8, DNE 3. | https://ubuntu.com/security/CVE-2026-41401 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||