Corosync is a clustering and high-availability middleware library that provides messaging and quorum functionality for critical infrastructure systems, despite maintaining a narrow product footprint. Its observed vulnerability profile centers on memory-safety and control-flow weaknesses including integer overflows, buffer overflows, and improper return-value checking, which are characteristic of C-based systems software handling untrusted cluster node communications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Corosync over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35091HIGH A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a spe | Apr 1, 2026 | 8.2 | 29 | NO | NO |
CVE-2025-30472CRITICAL Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a l | Mar 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2026-35092HIGH A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram | Apr 1, 2026 | 7.5 | 27 | NO | NO |
CVE-2018-1084HIGH corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. | Apr 12, 2018 | 7.5 | 26 | NO | NO |
CVE-2013-0250MEDIUM The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (c | Jun 6, 2014 | 5.0 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Corosync.
Media articles that mention a CVE ID that affects a product developed by Corosync — matched by CVE ID, not by vendor name.