CVE-2026-86098

ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 23:18

Updated : 2026-09-14 20:17


NVD link : CVE-2026-86098

Mitre link : CVE-2026-86098

CVE.ORG link : CVE-2026-86098


JSON object : View

Products Affected

No product.

CWE
CWE-787

Out-of-bounds Write