CVE-2026-43964 PUBLISHED

Assigner: mitre
Reserved: 04.05.2026 Published: 04.05.2026 Updated: 04.05.2026

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 3.7

Product Status

Vendor Postfix
Product Postfix
Versions Default: unaffected
  • affected from 2.3 to 3.8.16 (excl.)
  • affected from 3.9 to 3.9.10 (excl.)
  • affected from 3.10 to 3.10.9 (excl.)

References

Problem Types

  • CWE-193 Off-by-one Error CWE