CVE-2026-5720

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the allocated HTTP request buffer.
Configurations

Configuration 1 (hide)

cpe:2.3:a:miniupnp_project:miniupnpd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-17 22:16

Updated : 2026-06-29 14:22


NVD link : CVE-2026-5720

Mitre link : CVE-2026-5720

CVE.ORG link : CVE-2026-5720


JSON object : View

Products Affected

miniupnp_project

  • miniupnpd
CWE
CWE-125

Out-of-bounds Read

CWE-191

Integer Underflow (Wrap or Wraparound)