cvesecurityvulnerability
CVE-2026-19519: Claircore RPM Header Parser Crash Takes Down Container Vulnerability Scanners
CVE-2026-19519 is a denial-of-service vulnerability in claircore, the Go library behind Red Hat's Clair container scanner. A crafted RPM header in a container layer triggers an unchecked type assertion (CWE-617) that panics the indexer process. CVSS 4.3 MEDIUM.