Skip to main content
CRITICAL

CVE-2026-82439

CVSS v3

9.8

CRITICAL

EPSS Score

0.3 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its queue, and the shutdown path drained queues, but the queue object and its map entry remained for the life of the process. Function names come from the client and are not constrained to functions any topology has registered, so the number of retained entries is bounded only by the

Technical details

Published
2026-09-14
Last Modified
2026-09-14

Frequently asked questions

What is CVE-2026-82439?

Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its queue, and the shutdown path drained queues, but the queue object and its map entry remained for the life of the process. Function names come from the client and are not constrained to functions any topology has registered, so the number of retained entries is bounded only by the

Is CVE-2026-82439 actively exploited?

Active exploitation of CVE-2026-82439 has not been confirmed. Its EPSS score was 0.3% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-82439?

CVE-2026-82439 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2026-82439 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key