Out-of-Bounds Memory Disclosure in Network Protocol by Eclipse
CVE-2026-102712

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102712?

A vulnerability exists in the DTLS networking protocol where the parser improperly handles the session_id length during the initial ClientHello handshake. This flaw allows an unauthenticated peer to trigger an out-of-bounds read, leading to a potential disclosure of sensitive adjacent memory over the network. This disclosure occurs when the malicious input drives the read of up to 255 bytes, which are then echoed in the outgoing ServerHello response. Furthermore, the vulnerability is inherently exploitable upon the receipt of the first packet, compromising the affected system's security.

Affected Version(s)

NetX Duo 0 <= 6.5.1.202602

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cipher-creator
afldl
adawn0106
.