Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory…
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L N N 5.3 .0029 21.1 —
AFFECTED
Product Versions Fixed
GNU SASL unspecified —
TIMELINE
Jun 23 EXPLOIT PUBLISHED — CVE-2026-56968 (GNU SASL). Public exploit reference added.
Jun 23 Reserved by mitre
Jun 23 Published (CNA: mitre)
Jul 31 EXPLOIT PUBLISHED — CVE-2026-56968 (GNU SASL). Public exploit reference added.
Jul 31 RESCORED — CVE-2026-56968 (GNU SASL). CVSS 3.7 → 5.3 (NVD).
Description
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| June 23, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-56968 (GNU SASL). Public exploit reference added. |
| June 23, 2026 | Reserved | Reserved by mitre |
| June 23, 2026 | Published | Published (CNA: mitre) |
| July 31, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-56968 (GNU SASL). Public exploit reference added. |
| July 31, 2026 | RESCORED | RESCORED — CVE-2026-56968 (GNU SASL). CVSS 3.7 → 5.3 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| GNU | GNU SASL | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-56968 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.