GNOME Vulnerabilities and Affected Products
Vulnerabilities associated with librest.
Products
Clear product- GLib10 vulnerabilities
- libsoup5 vulnerabilities
- Gdk-Pixbuf3 vulnerabilities
- GIMP3 vulnerabilities
- libxml23 vulnerabilities
- Evolution Data Server2 vulnerabilities
- libgsf2 vulnerabilities
- Ekiga1 vulnerability
- Epiphany1 vulnerability
- Evolution1 vulnerability
- Fonts Viewer1 vulnerability
- gdkpixbuf1 vulnerability
- gdm1 vulnerability
- GDM31 vulnerability
- glade1 vulnerability
- gnome-remote-desktop1 vulnerability
- gnome-shell1 vulnerability
- gvdb1 vulnerability
- librest1 vulnerability
- libxslt1 vulnerability
- malcontent1 vulnerability
- NetworkManager1 vulnerability
- Pango1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-16615MEDIUM | Librest: weak random number generation in pkce implementationA flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAut… CWE-338Jul 22, 2026 | CVSS6.8v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |