Description
A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service condition.
Published: 2026-08-06
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack buffer overrun in CatchPulse can be leveraged to exhaust system resources, resulting in a denial‑of‑service condition. This overflow bypasses input bounds checks and matches CWE‑119, causing the application to crash or become unresponsive.

Affected Systems

The vulnerability affects SecureAge’s CatchPulse product. No specific versions are listed in the CVE record, so all installations of CatchPulse remain potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS base score of 5.5 categorizes the flaw as medium. EPSS information is not available, and the issue is not in the CISA KEV catalog. Because no attack vector is specified, it is reasonable to assume remote exploitation via crafted input, but the exact exploitation pathway remains undocumented. The risk of widespread exploitation is moderate pending additional intelligence.

Generated by OpenCVE AI on August 6, 2026 at 11:20 UTC.

Remediation

Vendor Solution

Users and administrators of affected products are advised to update to the latest versions.


OpenCVE Recommended Actions

  • Update CatchPulse to a version that contains the vendor’s fix.
  • Configure the application or network to limit the rate of incoming connections or requests to mitigate potential DoS attacks.
  • Monitor system logs and performance metrics for signs of abnormal resource consumption or application crashes.

Generated by OpenCVE AI on August 6, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Secureage
Secureage catchpulse
Weaknesses CWE-119
Vendors & Products Secureage
Secureage catchpulse

Thu, 06 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service condition.
Title Denial-of-service vulnerability in CatchPulse
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Secureage Catchpulse
cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-08-06T09:23:50.387Z

Reserved: 2026-06-18T04:11:38.685Z

Link: CVE-2026-55980

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T11:30:02Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer