VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks

2026-08-11T20:52:02Zbdc803f44cf7cc77c0796115269c83447d84e8b279c6bc7a6da0eae91ee4d9fd
CVE-2026-15657CVE-2026-15658CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-18412CVE-2026-18497CVE-2026-6726CVE-2026-6727CVE-2026-8496BOLACERT/CCIDORLLMOpenCartSGLangSOGoSSRFTPMTrueTypeXSSactive-exploitationcloud-deploymentcredential-exposurecryptographydefault-credentialsdenial-of-servicedirectory-traversalheap-buffer-overflowinformation-disclosurelocal-file-readmultiple-vulnerabilitiespayment-dataremote-code-executiontiming-side-channel

What happened

CERT/CC advisories describe multiple vulnerabilities across TPM 2.0 reference code, OpenCart, stb_truetype, SOGo, VPS.org deployment templates, SGLang, and foreUP. Impacts include unauthenticated or privileged remote code execution, directory traversal and web-shell creation, XSS with mailbox compromise, cryptographic key and credential disclosure, exposed databases and default secrets, SSRF and local file read, payment credential exposure, and broken object-level authorization. Several issues lack patches, while SOGo recommends upgrading to 5.12.8 or newer.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
bdc803f44cf7cc77c0796115269c83447d84e8b279c6bc7a6da0eae91ee4d9fd
Enrichment time
2026-08-11T20:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.