Skip to main content
Version: v1.2.x

CVE-2026-6368

CVE Details

Visit the official vulnerability details page for CVE-2026-6368 to learn more.

Initial Publication

08/10/2026

Last Update

08/12/2026

Third Party Dependency

glibc

NIST CVE Summary

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVE Severity

2.1

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Received

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.2.2⚠️ Impacted⚠️ Impacted
1.1.8⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.