CVE-2026-23556CWE-281

oxenstored keeps quota related use counts across domain destruction

Critical · published July 9, 2026

CVSS v4.0
9.4
EPSS
0%
Percentile
3.4
In the wild
Unconfirmed
What it is

When oxenstored is tearing a domain down, the node data is cleaned up

but the usage counts are leaked.

When the domain ID is eventually reused, the new domain can create fewer

nodes before beeing deemed to be over quota.

The record
Technical detail
CVSS v4.0
9.4 · CRITICAL
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
0.00137 · 3.4th percentile
Weakness
CWE-281 · Improper Preservation of Permissions
Published
2026-07-09T14:48Z
EPSS history
Timeline
  • 09 JUL 14:48Z
    oxenstored keeps quota related use counts across domain destruction
    cvelistv5