Client-Side TLS/DTLS Handshake Parsing Vulnerability in NetX Secure by Eclipse
CVE-2026-102728

Currently unrated

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102728?

The NetX Secure library contains a vulnerability in its TLS and DTLS handshake parsers, where it reads fields from a server-supplied message without proper validation of message length. This flaw allows for bounded out-of-bounds reads from a remotely accessible path when a client connects to a malicious or malformed server. Notably, the existing bounds checks trigger after the reads they are intended to secure, leaving systems exposed to potential exploitation through crafted messages.

Affected Version(s)

NetX Duo 0 <= 6.5.1.202602

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tinic
.