CVE-2026-78376

EUVD-2026-64858
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 19.23%
Debian logo
Debian Releases
Debian Product
Codename
webkit2gtk
bookworm
vulnerable
bookworm (security)
vulnerable
forky
vulnerable
sid
2.54.0-1
fixed
trixie
postponed
trixie (security)
2.54.0-1~deb13u1
fixed
wpewebkit
bookworm
ignored
forky
2.54.0-2
fixed
sid
2.54.0-2
fixed
trixie
ignored
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
webkitgtk
bionic
ignored
jammy
dne
noble
dne
resolute
dne
xenial
ignored
webkit2gtk
bionic
ignored
focal
ignored
jammy
ignored
noble
deferred
resolute
deferred
xenial
ignored
qtwebkit-source
bionic
ignored
jammy
dne
noble
dne
resolute
dne
xenial
ignored
qtwebkit-opensource-src
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
resolute
dne
xenial
ignored
wpewebkit
focal
ignored
jammy
ignored
noble
dne
resolute
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
webkit2gtk3
RHEL 8
0:2.54.0-1.el8_10
fixed
RHEL 9
0:2.54.0-1.el9_8
fixed
webkit2gtk3-devel
RHEL 8
0:2.54.0-1.el8_10
fixed
RHEL 9
0:2.54.0-1.el9_8
fixed
webkit2gtk3-jsc
RHEL 8
0:2.54.0-1.el8_10
fixed
RHEL 9
0:2.54.0-1.el9_8
fixed
webkit2gtk3-jsc-devel
RHEL 8
0:2.54.0-1.el8_10
fixed
RHEL 9
0:2.54.0-1.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
webkitgtk4
Amazon Linux 2
0:2.52.6-1.amzn2.0.2
fixed
webkitgtk4-devel
Amazon Linux 2
0:2.52.6-1.amzn2.0.2
fixed
webkitgtk4-jsc
Amazon Linux 2
0:2.52.6-1.amzn2.0.2
fixed
webkitgtk4-jsc-devel
Amazon Linux 2
0:2.52.6-1.amzn2.0.2
fixed