CVE-2026-16211

Source
https://cve.org/CVERecord?id=CVE-2026-16211
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16211.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16211
Published
2026-07-19T03:30:10Z
Modified
2026-10-08T02:49:53Z
Severity
  • 1.2 (Low) CVSS_V4 - CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
allegro Hostname Allocation assets.py AssetLastHostname.increment_hostname race condition
Details

A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. Executing a manipulation of the argument counter can lead to race condition. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-362"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16211.json"
}
References

Affected packages

Git / github.com/allegro/ralph

Affected ranges

Type
GIT
Repo
https://github.com/allegro/ralph
Events

Affected versions

20260609.*
20260609.1
Other
bcf65b994ef29fb3fc2e10b660e6288723d5209e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16211.json"