Heap-based Buffer Overflow in PcapPlusPlus by Seladb
CVE-2026-13590
Key Information:
- Vendor
Seladb
- Status
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13590?
A security flaw has been identified in PcapPlusPlus version 25.05, specifically in the Modbus Protocol Handler's function pcpp::ModbusLayer::getLength. This vulnerability results from improper handling of the length argument, which can lead to a heap-based buffer overflow. Attackers may exploit this issue remotely, though the complexity involved in executing the exploit remains high. A patch has been issued to mitigate the risk associated with this vulnerability, and users are strongly advised to apply it to enhance their security posture.
Affected Version(s)
PcapPlusPlus 25.05
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
