CVE-2026-29856: Aapanel
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Service (ReDoS) via a crafted input.
Affected products
- Aapanel Aapanel: version 7.57.0 only
Published 2026-03-18. Last modified 2026-06-17.