SCA: security update for irrd (GHSA-22m3-c7vp-49fj)

high Tenable Cloud Security Plugin ID 438348

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL
format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an
attacker can manipulate the HTTP Host header on a password reset or account creation request. The
confirmation link in the resulting email can then point to an attacker-controlled domain. Opening the link
in the email is sufficient to pass the token to the attacker, who can then use it on the real IRRD
instance to take over the account. A compromised account can then be used to modify RPSL objects
maintained by the account's mntners and perform other account actions. If the user had two-factor
authentication configured, which is required for users with override access, an attacker is not able to
log in, even after successfully resetting the password. This issue has been patched in versions 4.4.5 and
4.5.1. (CVE-2026-28681)

See Also

https://github.com/advisories/GHSA-22m3-c7vp-49fj

Plugin Details

Severity: High

ID: 438348

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 3/5/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.59

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-28681

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/4/2026

Vulnerability Publication Date: 3/4/2026

Reference Information

CVE: CVE-2026-28681