VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks
2026-08-14T20:52:02Z•4382871c71840e262f9729a3eafc67551bfc15658a2115e43779404d6eb954e7
CVE-2026-15657CVE-2026-15658CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-18412CVE-2026-18497CVE-2026-6726CVE-2026-6727CVE-2026-8496BOLACERT/CCIDOROpenCartSGLangSSRFTPMXSSactive-exploitationarbitrary-file-writeauthentication-bypasscredential-disclosurecryptographydefault-credentialsdenial-of-servicedirectory-traversalheap-buffer-overflowinformation-disclosureinformation-leakagelocal-file-readmultiple-vulnerabilitiespayment-dataremote-code-executiontiming-side-channelweb-shell
What happened
CERT/CC vulnerability notes report multiple serious flaws across TPM 2.0 reference code, OpenCart, stb_truetype, SOGo, VPS.org deployment templates, SGLang, and foreUP. Issues include cryptographic information leakage and timing attacks, path traversal enabling web-shell deployment, heap buffer overflow, actively exploited XSS with mailbox compromise, exposed default credentials and secrets, unauthenticated RCE and SSRF, and payment credential disclosure with broken object-level authorization. Several issues lack patches at publication; SOGo recommends upgrading to 5.12.8 or newer.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 4382871c71840e262f9729a3eafc67551bfc15658a2115e43779404d6eb954e7
- Enrichment time
- 2026-08-14T20:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.