Corosync
1 CVEs tracked since 2014. Since Jun 2014, none of them reached CISA KEV.
Corosync CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2014-06 | 1 | 0 |
Products
The products that kept showing up in Corosync's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Corosync.
- CVE-2026-35092Corosync: corosync: denial of service via integer overflow in join message validation7.5
- CVE-2026-35091Corosync: corosync: denial of service and information disclosure via crafted udp packet8.2
- CVE-2025-30472Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.9.0
- CVE-2018-1084corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.7.5
- CVE-2013-0250The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a craft...5.0
The record
- Peak rank
- #109 in Jun 2014
- Busiest month shown
- Jun 2014, 1 CVEs
- Months with a KEV entry
- 0 since Jun 2014
- Monthly snapshots
- 1 since 2014