{"id":"CVE-2026-1425","summary":"pymumu SmartDNS SVBC Record dns.c _dns_decode_SVCB_HTTPS stack-based overflow","details":"A security flaw has been discovered in pymumu SmartDNS up to 47.1. This vulnerability affects the function _dns_decode_rr_head/_dns_decode_SVCB_HTTPS of the file src/dns.c of the component SVBC Record Parser. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The patch is identified as 2d57c4b4e1add9b4537aeb403f794a084727e1c8. Applying a patch is advised to resolve this issue.","modified":"2026-08-12T16:24:46.951471Z","published":"2026-01-26T07:32:06.516Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1425.json","unresolved_ranges":[{"extracted_events":[{"introduced":"47.0"},{"last_affected":"47.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/pymumu/smartdns/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1425.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1425"},{"type":"ADVISORY","url":"https://vuldb.com/?id.342841"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.736827"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.342841"},{"type":"FIX","url":"https://github.com/pymumu/smartdns/commit/2d57c4b4e1add9b4537aeb403f794a084727e1c8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pymumu/smartdns","events":[{"introduced":"3e48a94b9875b74509c5265d740915e7c8e60315"},{"fixed":"2d57c4b4e1add9b4537aeb403f794a084727e1c8"}],"database_specific":{"extracted_events":[{"introduced":"47.1"},{"last_affected":"47.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["47.1","Release47.1"],"database_specific":{"vanir_signatures":[{"source":"https://github.com/pymumu/smartdns/commit/2d57c4b4e1add9b4537aeb403f794a084727e1c8","target":{"file":"src/dns.c"},"deprecated":false,"digest":{"line_hashes":["47936723472579650317540588921420773264","297295444819886776360825326696600298970","31837311719478478378871006974787145952","14918559670342219424111814079108165961","65893038981463212428264919369997831285","3532271727601454759440135402921217734"],"threshold":0.9},"id":"CVE-2026-1425-26677959","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"189241239471486783380937913167718436350","length":599},"id":"CVE-2026-1425-93acf2f1","signature_type":"Function","signature_version":"v1","source":"https://github.com/pymumu/smartdns/commit/2d57c4b4e1add9b4537aeb403f794a084727e1c8","target":{"file":"src/dns.c","function":"_dns_decode_rr_head"}},{"source":"https://github.com/pymumu/smartdns/commit/2d57c4b4e1add9b4537aeb403f794a084727e1c8","target":{"file":"src/dns.c","function":"_dns_decode_SVCB_HTTPS"},"deprecated":false,"digest":{"length":1497,"function_hash":"200354488342086936584005011630155940432"},"id":"CVE-2026-1425-fd6ceecd","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1425.json","vanir_signatures_modified":"2026-08-12T16:24:46Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}