Description
A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service condition.
Published: 2026-08-06
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack buffer overrun in CatchPulse can be exploited to exhaust system resources, leading to application crashes or unresponsiveness. The flaw bypasses input bounds checks and targets memory areas governed by CWE-121, resulting in a denial‑of‑service condition.

Affected Systems

The vulnerability affects SecureAge’s CatchPulse product. No specific versions are listed in the CVE record, so all installations of CatchPulse remain potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS base score of 5.5 categorizes the flaw as medium. EPSS information is not available, and the issue is not in the CISA KEV catalog. Because no attack vector is specified, it is reasonable to infer that remote exploitation is possible via crafted input; however, the exact exploitation pathway remains undocumented. The risk of widespread exploitation is moderate pending additional intelligence.

Generated by OpenCVE AI on August 6, 2026 at 16:51 UTC.

Remediation

Vendor Solution

Users and administrators of affected products are advised to update to the latest versions.


OpenCVE Recommended Actions

  • Update CatchPulse to a version that contains the vendor’s fix.
  • Configure the application or network to limit the rate of incoming connections or requests to mitigate potential DoS attacks.
  • Monitor system logs and performance metrics for signs of abnormal resource consumption or application crashes.

Generated by OpenCVE AI on August 6, 2026 at 16:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Thu, 06 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Secureage
Secureage catchpulse
Weaknesses CWE-119
Vendors & Products Secureage
Secureage catchpulse

Thu, 06 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service condition.
Title Denial-of-service vulnerability in CatchPulse
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Secureage Catchpulse
cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-08-06T12:23:49.712Z

Reserved: 2026-06-18T04:11:38.685Z

Link: CVE-2026-55980

cve-icon Vulnrichment

Updated: 2026-08-06T12:23:44.066Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T10:16:44.247

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-55980

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:00:11Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow