Skip to main content

CVE-2026-4438

CVE Details

Visit the official vulnerability details page for CVE-2026-4438 to learn more.

Initial Publication

03/20/2026

Last Update

04/07/2026

Third Party Dependency

glibc

NIST CVE Summary

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

CVE Severity

5.4

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.1.0-rc.1⚠️ Impacted⚠️ Impacted
1.0.7⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.