Heap Buffer Overflow in ntop nDPI Versions Prior to 6.0
CVE-2026-86098

8.3HIGH

Key Information:

Vendor

Ntop

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-86098?

The ntop nDPI software, prior to version 6.0, contains a heap buffer overflow vulnerability localized in the ndpi_json_string_escape function. This weakness occurs when the function writes beyond the boundaries set by the buffer provided by the caller. Attackers can exploit this vulnerability by sending specially crafted network packet data—such as TLS Server Name Indication (SNI), HTTP headers, or DNS names—that reaches ndpi_json_string_escape, ultimately leading to heap corruption. This flaw can have serious implications for the confidentiality and integrity of data processed by the affected versions.

Affected Version(s)

nDPI 0 < 6.0

nDPI 6.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.