{
  "id": "CVE-2026-104031",
  "url": "https://spydr.io/cve/CVE-2026-104031",
  "published": "2026-10-06T01:16:33.843Z",
  "modified": "2026-10-06T15:09:20.387Z",
  "score": 5.5,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
  "score_source": "redhat.com",
  "epss": 0.00095,
  "epss_percentile": 0.00625,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "none",
  "vendors": [
    "Red Hat"
  ],
  "products": [
    "Red Hat Enterprise Linux 10",
    "Red Hat Enterprise Linux 6",
    "Red Hat Enterprise Linux 7",
    "Red Hat Enterprise Linux 8",
    "Red Hat Enterprise Linux 9",
    "Red Hat OpenShift Container Platform 4"
  ],
  "cwes": [
    "CWE-772"
  ],
  "description": "A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this vulnerability by maintaining an open connection and repeatedly submitting valid requests, leading to memory exhaustion and a Denial of Service (DoS).",
  "status": "Awaiting Analysis",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 5.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-104031",
      "tags": []
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2479418",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-104031",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
