CVE-2026-23556CWE-281
oxenstored keeps quota related use counts across domain destruction
Critical · published July 9, 2026
What it is
When oxenstored is tearing a domain down, the node data is cleaned up
but the usage counts are leaked.
When the domain ID is eventually reused, the new domain can create fewer
nodes before beeing deemed to be over quota.
The record
Technical detail
- CVSS v4.0
- 9.4 · CRITICAL
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS
- 0.00137 · 3.4th percentile
- Weakness
- CWE-281 · Improper Preservation of Permissions
- Published
- 2026-07-09T14:48Z
EPSS history
Timeline