CVE-2026-64773
Last modified
CVE-2026-64773 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Container | >= 0.3.0, < 1.2.0 |
References
- https://github.com/apple/container/security/advisories/GHSA-wg28-286f-56v6Patch, Vendor Advisory, Mitigation
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-64773?
How severe is CVE-2026-64773?
How do I fix CVE-2026-64773?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64768An out-of-bounds read issue was addressed with improved inpu…8.1
- CVE-2026-64769An out-of-bounds write issue was addressed with improved bou…9.8
- CVE-2026-6477Use of inherently dangerous function PQfn(..., result_is_int…8.8
- CVE-2026-64770An out-of-bounds write issue was addressed with improved bou…9.8
- CVE-2026-64771A buffer overflow was addressed with improved bounds checkin…9.8
- CVE-2026-64772An out-of-bounds write issue was addressed with improved inp…9.8
- CVE-2026-64774An integer overflow was addressed with improved input valida…9.8
- CVE-2026-64775A memory initialization issue was addressed with improved me…9.8
- CVE-2026-64776The issue was addressed with improved bounds checks. This is…5.5
- CVE-2026-64777A malicious builder peer may be able to request an in-contex…4.3
- CVE-2026-64778The issue was addressed with improved checks. This issue is …6.5
- CVE-2026-64779A memory corruption vulnerability was addressed with improve…3.1
Are you affected by CVE-2026-64773?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
