{"id":"AZL-95490","summary":"CVE-2026-65819 affecting package telegraf 1.31.0-28","details":"gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through DecodingLayerParser or DecodeFromBytes to trigger an unrecovered panic and remotely deny service.  A patch commit is available at 210f25f.","modified":"2026-08-28T17:48:13.790404386Z","published":"2026-08-07T20:16:52Z","upstream":["CVE-2026-65819"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65819"}],"affected":[{"package":{"name":"telegraf","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/telegraf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.31.0-28"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95490.json"}}],"schema_version":"1.9.0"}