PAN-SA-2026-0006 Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS

Informational
Description
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the affected OSS package, PAN-OS does not offer any scenarios required for an attacker to successfully exploit these vulnerabilities and is not impacted.
| CVE | Summary |
|---|---|
| CVE-2023-2176 | PAN-OS is not affected as PAN-OS does not use RDMA. |
| CVE-2023-5633 | PAN-OS is not affected as PAN-OS as the prerequisite conditions needed to be vulnerable do not exists in PAN-OS. |
| CVE-2023-28464 | PAN-OS is not affected as PAN-OS does not use the Bluetooth subsystem. |
| CVE-2024-0646 | PAN-OS is not affected as PAN-OS does not use the function splice() with a ktls socket as the destination. |
| CVE-2024-36971 | PAN-OS is not affected as PAN-OS does not use the vulnerable function __dst_negative_advice(). |
| CVE-2024-36886 | PAN-OS is not affected as PAN-OS does not use the vulnerable function tipc_buf_append(). |
| CVE-2025-57052 | This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable cjson library. |
| CVE-2026-27654 | PAN-OS is not affected as PAN-OS does not use the vulnerable DAV module. |
| CVE-2026-49975 | PAN-OS is not affected. The WebUI, GlobalProtect Portal, and Gateway interfaces do not use HTTP/2. |
| CVE-2026-55200 | PAN-OS is not affected as PAN-OS does not have libssh2. |
| CVE-2023-51767 | PAN-OS is not affected because of our underlying system architecture and security controls. |
| CVE-2023-38408 | PAN-OS is not affected as PAN-OS does not have SSH-agent. |
| CVE-2019-16905 | PAN-OS is not affected as PAN-OS has custom OpenSSH packages that do not support XMSS. |
| CVE-2026-34197 | PAN-OS is not affected as PAN-OS does not use Apache ActiveMQ Broker and Apache ActiveMQ. |
| CVE-2026-21265 | PAN-OS is not affected as PAN-OS does not have Microsoft Secure Boot certificates. |
| CVE-2026-35386 | PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS. |
| CVE-2026-35387 | PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS. |
| CVE-2026-35388 | PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS. |
| CVE-2026-35414 | PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS. |
| CVE-2026-59995 | PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS. |
| CVE-2026-59996 | PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS. |
| CVE-2026-59997 | PAN-OS is not affected as PAN-OS does not have the vulnerable OpenSSH internal-sftp subsystem. |
| CVE-2026-59998 | PAN-OS is not affected as PAN-OS does not have GSSAPI authentication. |
| CVE-2026-59999 | PAN-OS is not affected as PAN-OS does not enable SSH TCP forwarding or tunneling. |
| CVE-2026-60000 | PAN-OS is not affected as PAN-OS does not have GSSAPI authentication. |
| CVE-2019-0217 | PAN-OS is not affected as the prerequisite conditions needed to be vulnerable do not exist in PAN-OS. |
| CVE-2019-10092 | AN-OS is not affected as PAN-OS does not have mod_proxy. |
| CVE-2019-10098 | PAN-OS is not affected as PAN-OS does not have mod_proxy. |
| CVE-2020-14040 | AN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS. |
| CVE-2020-28463 | PAN-OS is not affected as PAN-OS uses Red Hat Enterprise Linux packages where this vulnerability does not impact the system. |
| CVE-2020-29652 | PAN-OS is not affected as PAN-OS does not have the golang.org/x/crypto/ssh package. |
| CVE-2020-9283 | AN-OS is not affected as PAN-OS does not have the golang.org/x/crypto/ssh package. |
| CVE-2021-33193 | PAN-OS is not affected as PAN-OS does not have mod_proxy. |
| CVE-2021-36160 | PAN-OS is not affected as PAN-OS does not have mod_proxy_uwsgi. |
| CVE-2021-44224 | PAN-OS is not affected as PAN-OS does not have Apache HTTP Server as a forward or reverse proxy. |
| CVE-2022-22719 | PAN-OS is not affected as PAN-OS does not have mod_lua. |
| CVE-2023-27522 | PAN-OS is not affected as PAN-OS does not have mod_proxy_uwsgi. |
| CVE-2024-38474 | PAN-OS is not affected as PAN-OS does not configure unsafe RewriteRules with backreferences or variable substitution. |
| CVE-2024-38476 | AN-OS is not affected as PAN-OS does not have backend application handlers vulnerable to internal redirect exploitation. |
| CVE-2024-38477 | PAN-OS is not affected as PAN-OS does not have mod_proxy. |
| CVE-2024-7254 | PAN-OS is not affected as PAN-OS uses the underlying Red Hat Enterprise Linux packages which are not affected. |
| CVE-2026-0994 | PAN-OS is not affected as PAN-OS does not parse untrusted nested google.protobuf. |
| CVE-2026-33186 | PAN-OS is not affected as PAN-OS does not have path-based authorization interceptors with fallback-allow policies. |
| CVE-2026-39820 | PAN-OS is not affected as PAN-OS does not have first-party code parsing mail via net/mail. |
| CVE-2026-39836 | PAN-OS is not affected as PAN-OS does not have the vulnerable Windows functions. |
Product Status
| Versions | Affected | Unaffected |
|---|---|---|
| PAN-OS | None | All |
Exploitation Status
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Solution
The OSS CVEs are fixed in the respective PAN-OS versions.
CPE Applicability
Timeline
Initial Publication