Cesnet
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Cesnet product.
RSS Feeds for Cesnet security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Cesnet products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Cesnet Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 1 vulnerability in Cesnet with an average score of 7.5 out of ten. Cesnet did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 7.50 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 3 | 6.10 |
| 2022 | 0 | 0.00 |
| 2021 | 5 | 7.50 |
| 2020 | 9 | 7.50 |
| 2019 | 3 | 9.80 |
It may take a day or so for new Cesnet vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Cesnet Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-44673 | May 14, 2026 |
libyang <5.2.15 LYB parser heap overflowlibyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15. |
|
| CVE-2023-26917 | Apr 11, 2023 |
libyang NULL pointer deref in lysp_stmt_validate_value before 2.1.30libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_mem.c. |
|
| CVE-2023-26916 | Apr 03, 2023 |
NULL Deref in libyang 2.0.164-2.1.30 via lys_parse_memlibyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c. |
|
| CVE-2016-15014 | Jan 07, 2023 |
ownCloud CESNET theme-cesnet resetpassword.php creds mishandle (<=1.x)A vulnerability has been found in CESNET theme-cesnet up to 1.x on ownCloud and classified as problematic. Affected by this vulnerability is an unknown functionality of the file cesnet/core/lostpassword/templates/resetpassword.php. The manipulation leads to insufficiently protected credentials. Attacking locally is a requirement. Upgrading to version 2.0.0 is able to address this issue. The identifier of the patch is 2b857f2233ce5083b4d5bc9bfc4152f933c3e4a6. It is recommended to upgrade the affected component. The identifier VDB-217633 was assigned to this vulnerability. |
|
| CVE-2021-28902 | May 20, 2021 |
In function read_yin_container() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULLIn function read_yin_container() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL, which leads to the operation of retval->ext[r]->flags that results in a crash. |
|
| CVE-2021-28903 | May 20, 2021 |
A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem()A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem(). lyxml_parse_elem() function will be called recursively, which will consume stack space and lead to crash. |
|
| CVE-2021-28904 | May 20, 2021 |
In function ext_get_plugin() in libyang <= v1.0.225, it doesn't check whether the value of revision is NULLIn function ext_get_plugin() in libyang <= v1.0.225, it doesn't check whether the value of revision is NULL. If revision is NULL, the operation of strcmp(revision, ext_plugins[u].revision) will lead to a crash. |
|
| CVE-2021-28905 | May 20, 2021 |
In function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULLIn function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULL. But in some cases, node->module can be null, which triggers a reachable assertion (CWE-617). |
|
| CVE-2021-28906 | May 20, 2021 |
In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULLIn function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL, which leads to the operation of retval->ext[r]->flags that results in a crash. |
|
| CVE-2020-5281 | Mar 25, 2020 |
In Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from Perun LDAPIn Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from Perun LDAP. Issue is fixed in version 3.9.1 by sanitisation of the input. |
|