Palo Alto Networks Security Advisories / PAN-SA-2026-0006

PAN-SA-2026-0006 Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS


Informational

Description

The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the affected OSS package, PAN-OS does not offer any scenarios required for an attacker to successfully exploit these vulnerabilities and is not impacted.

CVESummary
CVE-2023-2176PAN-OS is not affected as PAN-OS does not use RDMA.
CVE-2023-5633PAN-OS is not affected as PAN-OS as the prerequisite conditions needed to be vulnerable do not exists in PAN-OS.
CVE-2023-28464PAN-OS is not affected as PAN-OS does not use the Bluetooth subsystem.
CVE-2024-0646PAN-OS is not affected as PAN-OS does not use the function splice() with a ktls socket as the destination.
CVE-2024-36971PAN-OS is not affected as PAN-OS does not use the vulnerable function __dst_negative_advice().
CVE-2024-36886PAN-OS is not affected as PAN-OS does not use the vulnerable function tipc_buf_append().
CVE-2025-57052This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable cjson library.
CVE-2026-27654PAN-OS is not affected as PAN-OS does not use the vulnerable DAV module.
CVE-2026-49975PAN-OS is not affected. The WebUI, GlobalProtect Portal, and Gateway interfaces do not use HTTP/2.
CVE-2026-55200PAN-OS is not affected as PAN-OS does not have libssh2.
CVE-2023-51767PAN-OS is not affected because of our underlying system architecture and security controls.
CVE-2023-38408PAN-OS is not affected as PAN-OS does not have SSH-agent.
CVE-2019-16905PAN-OS is not affected as PAN-OS has custom OpenSSH packages that do not support XMSS.
CVE-2026-34197PAN-OS is not affected as PAN-OS does not use Apache ActiveMQ Broker and Apache ActiveMQ.
CVE-2026-21265PAN-OS is not affected as PAN-OS does not have Microsoft Secure Boot certificates.
CVE-2026-35386PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS.
CVE-2026-35387PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS.
CVE-2026-35388PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS.
CVE-2026-35414PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS.
CVE-2026-59995PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS.
CVE-2026-59996PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS.
CVE-2026-59997PAN-OS is not affected as PAN-OS does not have the vulnerable OpenSSH internal-sftp subsystem.
CVE-2026-59998PAN-OS is not affected as PAN-OS does not have GSSAPI authentication.
CVE-2026-59999PAN-OS is not affected as PAN-OS does not enable SSH TCP forwarding or tunneling.
CVE-2026-60000PAN-OS is not affected as PAN-OS does not have GSSAPI authentication.
CVE-2019-0217PAN-OS is not affected as the prerequisite conditions needed to be vulnerable do not exist in PAN-OS.
CVE-2019-10092AN-OS is not affected as PAN-OS does not have mod_proxy.
CVE-2019-10098PAN-OS is not affected as PAN-OS does not have mod_proxy.
CVE-2020-14040AN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS.
CVE-2020-28463PAN-OS is not affected as PAN-OS uses Red Hat Enterprise Linux packages where this vulnerability does not impact the system.
CVE-2020-29652PAN-OS is not affected as PAN-OS does not have the golang.org/x/crypto/ssh package.
CVE-2020-9283AN-OS is not affected as PAN-OS does not have the golang.org/x/crypto/ssh package.
CVE-2021-33193PAN-OS is not affected as PAN-OS does not have mod_proxy.
CVE-2021-36160PAN-OS is not affected as PAN-OS does not have mod_proxy_uwsgi.
CVE-2021-44224PAN-OS is not affected as PAN-OS does not have Apache HTTP Server as a forward or reverse proxy.
CVE-2022-22719PAN-OS is not affected as PAN-OS does not have mod_lua.
CVE-2023-27522PAN-OS is not affected as PAN-OS does not have mod_proxy_uwsgi.
CVE-2024-38474PAN-OS is not affected as PAN-OS does not configure unsafe RewriteRules with backreferences or variable substitution.
CVE-2024-38476AN-OS is not affected as PAN-OS does not have backend application handlers vulnerable to internal redirect exploitation.
CVE-2024-38477PAN-OS is not affected as PAN-OS does not have mod_proxy.
CVE-2024-7254PAN-OS is not affected as PAN-OS uses the underlying Red Hat Enterprise Linux packages which are not affected.
CVE-2026-0994PAN-OS is not affected as PAN-OS does not parse untrusted nested google.protobuf.
CVE-2026-33186PAN-OS is not affected as PAN-OS does not have path-based authorization interceptors with fallback-allow policies.
CVE-2026-39820PAN-OS is not affected as PAN-OS does not have first-party code parsing mail via net/mail.
CVE-2026-39836PAN-OS is not affected as PAN-OS does not have the vulnerable Windows functions.

Product Status

VersionsAffectedUnaffected
PAN-OSNoneAll

Exploitation Status

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Solution

The OSS CVEs are fixed in the respective PAN-OS versions.

CPE Applicability

Timeline

Initial Publication
© 2026 Palo Alto Networks, Inc. All rights reserved.