Improper Length Checking in HTTP Requests in Affected Product by Vendor
CVE-2026-8047

8.7HIGH

What is CVE-2026-8047?

The vulnerability arises from inadequate length validation when processing incoming HTTP requests, which may lead to a size-limited out-of-bounds write. An unauthenticated remote attacker could exploit this weakness, potentially resulting in a denial of service condition through system crashes on the impacted device. It is crucial for users to apply necessary patches and updates to mitigate this vulnerability.

Affected Version(s)

CODESYS Control for BeagleBone SL 4.15.0.0 < 4.21.0.0

CODESYS Control for emPC-A/iMX6 SL 4.15.0.0 < 4.21.0.0

CODESYS Control for IOT2000 SL 4.15.0.0 < 4.21.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.