Logo
vulnerabilityCVE-2026-32772
Name
CVE-2026-32772
Source
NVD ( link)Debian ( link)
Description
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
inetutils
Exploitable

Vulnerability Ratings#


3.4
CVSSv31
4.7
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
2.7
Patched
yocto
scarthgap
2.5
Patched

Resolved with patches#


inetutils (yocto:master)

#
Title
Author
Resolve
1
telnet: don't leak the value of unexported environment
Collin Funk <collin.funk1@gmail.com>
CVE-2026-32772

inetutils (yocto:scarthgap)

#
Title
Author
Resolve
1
telnet: don't leak the value of unexported environment variables
Collin Funk <collin.funk1@gmail.com>
CVE-2026-32772