{
  "from_raw": "Colm O hEigeartaigh <coheigea@apache.org>",
  "from": "Colm O hEigeartaigh <co...@apache.org>",
  "gravatar": "7760700ec800e9fa0453ac51f2db8802",
  "to": "an...@apache.org,\n de...@directory.apache.org",
  "subject": "CVE-2026-57915: Apache Kerby: Kerberos Pre-Authentication Bypass",
  "message-id": "<90bb8d8f-6ab4-151d-eb6d-7c22a2e883f1@apache.org>",
  "mid": "3d08wnn0z49mxofyqvo8613kqpsoxdo2",
  "permalinks": [
    "3d08wnn0z49mxofyqvo8613kqpsoxdo2",
    "r2ec071115b56bd39cf00362a4a95292ed788ccd8aa8dcde4da64f5ae@<announce.apache.org>"
  ],
  "dbid": "6f950e4252198cff4f6c931406e920087c33dea3430ff63b7b9b3891ac1bcb52",
  "cc": "de...@directory.apache.org",
  "epoch": 1782470810,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/06/26 10:46:50",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Kerby (org.apache.kerby:kerb-server) before 2.1.2\n\nDescription:\n\nIt is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.\n\nReferences:\n\nhttps://directory.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-57915\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Kerby (org.apache.kerby:kerb-server) before 2.1.2\n\nDescription:\n\nIt is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sen",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2285,
  "id": "3d08wnn0z49mxofyqvo8613kqpsoxdo2"
}