neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parse_domain function.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade neon27 | Jul 30, 2024 | Aug 27, 2008 |
| Freebsd | — | Upgrade neon28 | Dec 10, 2025 | Sep 12, 2008 |
| Suse | — | Upgrade neonUpgrade libneon27Upgrade libneon27-32bitUpgrade libneon27-x86Upgrade libneon-devel | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libneon25Upgrade libneon27Upgrade libneon27-gnutls | Nov 8, 2024 | Aug 27, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub