VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks

2026-08-14T20:52:02Z4382871c71840e262f9729a3eafc67551bfc15658a2115e43779404d6eb954e7
CVE-2026-15657CVE-2026-15658CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-18412CVE-2026-18497CVE-2026-6726CVE-2026-6727CVE-2026-8496BOLACERT/CCIDOROpenCartSGLangSSRFTPMXSSactive-exploitationarbitrary-file-writeauthentication-bypasscredential-disclosurecryptographydefault-credentialsdenial-of-servicedirectory-traversalheap-buffer-overflowinformation-disclosureinformation-leakagelocal-file-readmultiple-vulnerabilitiespayment-dataremote-code-executiontiming-side-channelweb-shell

What happened

CERT/CC vulnerability notes report multiple serious flaws across TPM 2.0 reference code, OpenCart, stb_truetype, SOGo, VPS.org deployment templates, SGLang, and foreUP. Issues include cryptographic information leakage and timing attacks, path traversal enabling web-shell deployment, heap buffer overflow, actively exploited XSS with mailbox compromise, exposed default credentials and secrets, unauthenticated RCE and SSRF, and payment credential disclosure with broken object-level authorization. Several issues lack patches at publication; SOGo recommends upgrading to 5.12.8 or newer.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
4382871c71840e262f9729a3eafc67551bfc15658a2115e43779404d6eb954e7
Enrichment time
2026-08-14T20:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks · Baitaphish