CVE-2026-58012

MEDIUM
Published June 30, 2026

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the...

Full CISO analysis pending enrichment.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
vLLM pip — No patch
92.7K 95 dependents Pushed 3d ago 26% patched ~47d to patch Full package profile →
vLLM pip — No patch
92.7K 95 dependents Pushed 3d ago 26% patched ~47d to patch Full package profile →
GLib — — No patch
cert-manager/cert-manager-istio-csr-rhel9 — — No patch
cert-manager/cert-manager-operator-rhel9 — — No patch
cert-manager/cert-manager-trust-manager-rhel9 — — No patch
cert-manager/jetstack-cert-manager-acmesolver-rhel9 — — No patch
cert-manager/jetstack-cert-manager-rhel9 — — No patch
discovery/discovery-server-rhel9 — — No patch
discovery/discovery-ui-rhel9 — — No patch
glib2 — — No patch
mingw-glib2 — — No patch
rhai/base-image-cpu-rhel9 — — No patch
rhai/base-image-cuda-rhel9 — — No patch
rhai/base-image-rocm-rhel9 — — No patch
rhai/base-image-spyre-rhel9 — — No patch
rhai/base-image-tpu-rhel9 — — No patch
rhaiis/model-opt-cuda-rhel9 — — No patch
rhui5/cds-kubernetes-rhel9 — — No patch
rhui5/cds-kubernetes-tp-rhel9 — — No patch
rhui5/cds-rhel9 — — No patch
rhui5/haproxy-rhel9 — — No patch
rhui5/installer-rhel9 — — No patch
rhui5/installer-tp-rhel9 — — No patch
rhui5/rhua-rhel9 — — No patch
rhui5/rhua-tp-rhel9 — — No patch

How severe is it?

CVSS 3.1
6.5 / 10
EPSS
N/A
Exploitation Status
No known exploitation
Sophistication
N/A

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Unchanged
C Low
I None
A Low

What should I do?

No patch available

Monitor for updates. Consider compensating controls or temporary mitigations.

Which compliance frameworks are affected?

Compliance analysis pending. Sign in for full compliance mapping when available.

Frequently Asked Questions

What is CVE-2026-58012?

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.

Is CVE-2026-58012 actively exploited?

No confirmed active exploitation of CVE-2026-58012 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-58012?

No patch is currently available. Monitor vendor advisories for updates.

What is the CVSS score for CVE-2026-58012?

CVE-2026-58012 has a CVSS v3.1 base score of 6.5 (MEDIUM).

What are the technical details?

Original Advisory

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.

Weaknesses (CWE)

CWE-126 — Buffer Over-read: The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

References

Timeline

Published
June 30, 2026
Last Modified
September 30, 2026
First Seen
September 30, 2026

Related Vulnerabilities