CVE-2026-86098: Schwachstellen-Eintrag (NVD)
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-05 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-86098 | ntop nDPI up to 5.x ndpi_json_string_escape heap-based overflow (Nessus ID 343095)
A vulnerability labeled as critical has been found in ntop nDPI up to 5.x. This affects the function ndpi_json_string_escape. The manipulation results in heap-based buffer overflow. This vulnerability is reported as CVE-2026-86098. The atta