Unknown · Memberlist · CVE-2026-14362
**Name of the Vulnerable Software and Affected Versions**
memberlist versions prior to 0.6.0
**Description**
A denial-of-service issue exists in the push/pull state handling. An attacker with network access to the gossip port can exhaust memory on a receiving node, causing the process to terminate.
**Recommendations**
Update to version 0.6.0.