LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-86098

Published
CVSS7.4
Severityhigh
WeaknessCWE-787
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Description

ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-86098

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-86098.