{"id":"AZL-99945","summary":"CVE-2026-86098 affecting package ntopng 5.2.1-6","details":"ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.","modified":"2026-09-12T05:27:53Z","published":"2026-09-04T23:18:03Z","upstream":["CVE-2026-86098"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86098"}],"affected":[{"package":{"name":"ntopng","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/ntopng"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"5.2.1-6"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99945.json"}}],"schema_version":"1.9.0"}