Wicked
6 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Wicked, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Wicked CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 2 |
| 2026-09 | 0 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High3
- Medium2
Latest CVEs
The 6 most recently published vulnerabilities affecting Wicked.
- CVE-2026-71402wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total length5.4
- CVE-2026-71401wicked: integer underflow of the UDP length in ni_capture_inspect_udp_header() leads to an out-of-bounds read—
- CVE-2026-44932indirect remote shell command injection via unsanitized DHCP options in wicked8.8
- CVE-2020-7217An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.7.5
- CVE-2020-7216An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.7.5
- CVE-2013-4413Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot ...5.0
Product grouping is registry-driven, with AI assist and human review. How it works