CVE-2026-86098

HIGH
7.4CVSS v3
CVSS v2
0.35% EPSS (exploit probability)
CWE-787CWE

Description

ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.

CVSS v3 vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references