CVE-2026-10275: global buffer overflow during key pair generation tests due to missing input validation (bsc#1267246).
CVE-2026-40528: stack and heap buffer overrun in the do_key_value() function due to missing length check allows for
memory corruption via a crafted profile configuration file (bsc#1266963).