Skip to main content

CVE-2026-4438

CVE Details​

Visit the official vulnerability details page for CVE-2026-4438 to learn more.

Initial Publication​

03/20/2026

Last Update​

07/14/2026

Third Party Dependency​

libc6

NIST CVE Summary​

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

CVE Severity​

5.4

Our Official Summary​

Investigation is ongoing to determine how this vulnerability affects our products.

Status​

Modified

Affected Products & Versions​

VersionPaletteAIPaletteAI VerteX
1.4.0⚠️ Impacted⚠️ Impacted
1.3.2⚠️ Impacted⚠️ Impacted
1.2.2⚠️ Impacted⚠️ Impacted

Revision History​

No revisions available.