CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-48863

highCVSS 7.5covered by 2 sourcesfirst seen 2026-07-14
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.

CSIRTS triage

What
A stack-based buffer overflow in eddsa pgp signature verification allows denial of service.
Who is affected
Users of Libsolv are affected.
Urgency
Remediation is high urgency due to the potential for exploitation.
Action
Update Libsolv to the latest version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-48863

Get an email if CVE-2026-48863 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-48863

CVE.org record

Embed the live status

CVE-2026-48863 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-48863 status](https://www.csirts.com/badge/CVE-2026-48863)](https://www.csirts.com/cve/CVE-2026-48863)