CVE-2026-107778: Mit KRB5

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos clients to crash services by sending mismatched KRB-CRED arrays. Attackers can send forwarded credentials with more tickets than ticket_info entries through gss_accept_sec_context() to crash GSS-API acceptor services, causing denial of service.

Affected products

  • Mit KRB5: up to and including 1.22.2

Published 2026-10-08. Last modified 2026-10-09.