VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks

2026-08-12T20:52:01Z1c7509369ec33dcf0c8309b45551b3ecaff756388b2c48b1c1fab9895daf1c81
CVE-2026-15657CVE-2026-15658CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-18412CVE-2026-18497CVE-2026-6726CVE-2026-6727CVE-2026-8496CERT/CCactive-exploitationbroken-object-level-authorizationcloud-securitycryptographydefault-credentialsdeserializationdirectory-traversalheap-buffer-overflowidorinformation-disclosurellm-securitylocal-file-readremote-code-executionside-channelssrfstored-xssvulnerability

What happened

CERT/CC advisories describe multiple 2026 vulnerabilities affecting TPM 2.0 reference code, OpenCart, stb_truetype, SOGo, VPS.org deployment templates, SGLang, and foreUP. Impacts include unauthenticated or privileged remote code execution, timing and information-leakage side channels, directory traversal to web-shell placement, memory disclosure and denial of service, stored or reflected XSS with mailbox compromise, default-credential exposure, SSRF and local file disclosure, credential and payment-data exposure, and broken object-level authorization. Several issues lack patches, while SOGo 5

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
1c7509369ec33dcf0c8309b45551b3ecaff756388b2c48b1c1fab9895daf1c81
Enrichment time
2026-08-12T20:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks · Baitaphish