Client-Side TLS/DTLS Handshake Parsing Vulnerability in NetX Secure by Eclipse
CVE-2026-102728
Currently unrated
What is CVE-2026-102728?
The NetX Secure library contains a vulnerability in its TLS and DTLS handshake parsers, where it reads fields from a server-supplied message without proper validation of message length. This flaw allows for bounded out-of-bounds reads from a remotely accessible path when a client connects to a malicious or malformed server. Notably, the existing bounds checks trigger after the reads they are intended to secure, leaving systems exposed to potential exploitation through crafted messages.
Affected Version(s)
NetX Duo 0 <= 6.5.1.202602
