discover_handler in the library /lib/sbi/nghttp2-server.c of the component NRF. The manipulation results in use after free.This vulnerability is reported as CVE-2026-8746. The attack can be launched remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.