CVE-2026-94640

HIGH Status: Awaiting Analysis

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedure Call) statistics in unbounded in-memory lists, leading to persistent memory growth and increased CPU usage. This can degrade or exhaust service availability.

Published
September 22, 2026 4:18 PM
Last Modified
September 22, 2026 7:37 PM
Source
[email protected]

Weaknesses (CWE)

CWE-400

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.