CVE-2026-107708: Mit KRB5
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.
Affected products
- Mit KRB5: up to and including 1.22.2
Published 2026-10-08. Last modified 2026-10-08.