miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the allocated HTTP request buffer.
References
| Link | Resource |
|---|---|
| https://github.com/miniupnp/miniupnp/ | Product |
| https://github.com/miniupnp/miniupnp/commit/f56bd09b2f2650126b832c5f30a65a09e28167fa | Patch |
| https://www.vulncheck.com/advisories/miniupnpd-integer-underflow-soapaction-header-parsing | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2026-04-17 22:16
Updated : 2026-06-29 14:22
NVD link : CVE-2026-5720
Mitre link : CVE-2026-5720
CVE.ORG link : CVE-2026-5720
JSON object : View
Products Affected
miniupnp_project
- miniupnpd
