{"id":"CVE-2026-86098","summary":"ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape","details":"ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.","modified":"2026-09-06T08:01:49.380032Z","published":"2026-09-04T22:38:48.064Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86098.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86098.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86098"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ntop-ndpi-before-6.0-heap-buffer-overflow-via-ndpi-json-string-escape"},{"type":"FIX","url":"https://github.com/ntop/nDPI/commit/94e82c1de12323d992895830231865736a8abf2c"},{"type":"PACKAGE","url":"https://github.com/ntop/nDPI"},{"type":"ARTICLE","url":"https://github.com/ntop/nDPI/blob/5.0/src/lib/ndpi_serializer.c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ntop/ndpi","events":[{"introduced":"0"},{"fixed":"1a5293396337f9a72dfee1fa070b2c4b0a0a3aaf"},{"fixed":"94e82c1de12323d992895830231865736a8abf2c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.0"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["3.4","1.8","1.7","1.6"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/ntop/ndpi/commit/94e82c1de12323d992895830231865736a8abf2c","target":{"file":"src/lib/ndpi_serializer.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["77863997582183953390710588542376021313","147502704576664472300282157911722925648","96570148280714861797572246311630892535","334644483383646816851002073713357190825","19661180907052702521767752215566748758","226950423075280964055483833906349232121","274471951790236557593996493083083925708","65828254928581862687310362114347723696","237485888713748843813398498414972257139","11666342114755945662604680843628823704","170866638222168898057531991665007518450","264832559322843020138688186919445994729","149304374845634129850502496645892401500","85994699923379257440463020825137494701","247146489579623181354467614729602539384","77880063521139272283082421011275206799","262279041703779043140823055295084587334","195528874652413483982202588548983154015","326976811585137401754870200980285092492","236900533611274816200368595099432893042","69142212055528576329627245748659669223","118471777348936388606322114710960245678","243684626674322571641010581368418017084","112445774395711035676442714529036834199","80048805926730760601529556601100598536","132800526413931665934373158928737425584","158461685764717105338056579220380054131","272500502676386680526668993553469143246","145794558603709342994601950827700044955","79535988466281736365004883152150428564","31769944820559108702800427928070286641","44878374215903181198024419735760785490","306344388675246464923742297705228540498","270223989687887248882407790345819327105","97154806322430438572553262535328832833","222884076241042413002286980270470734489","54096694726120921497332417603609541020","204663675781728630996730309414676959244","99694347052577056598388212619222634783","88361288607225931708655055870498570729","222681361095376753364230629084016577549","313140536789095039104718948814538241742","296410885754330168200454684500842413802","180785147902933800152589078385327882472","59137002734284394603567879418221168449","198325381472685137664047306023938057599","77416428295188942027021510529752946468","303275291274389700248314450329061278270","29336870107087007383208458473673816709","265706087877412716352872521730280102933","253064296221509046115534719444065219989","297375012672795744832822524252497327885","196924768042366298894148922901549921736","159590990460902629733729364513469138941","279230756845837635284235490266237560132","340122163776347867971960902501490189847","133446655696125610664928678502186308893","246426931058871917385353355050422822399","311972030888392914110978696500234370495","223477605454239194443504261185252607356","186428825111813476191904334387082314728","150166324213711157113859828234070371178","139161432041803210182024999962432857826","246308731526224126624898711389651812021","195526942396625257434119436648265686896","132197235297579775207803173423853860458","108156537253364469160447571383261463794","238942995341335719008097840896548792342","183086758991429447845541237409917270671","309134374926344960698085241379714134369","117505711931697678778158414408077459709","76851618623967289521556689468027733689","117171616821105569368009601085819770874","78027394617548494996137393109876310013","24680367301293424775790029920452533304","332464873947065473834548801533188860107","272805571894843891151852122980443657201","119170779466295809413766267805296350814","27666031590988447302828933620396404811","142680511153357068782097514182455195194","91380883351028805998831684211592633146","113077090411750457547392142310718776597"]},"id":"CVE-2026-86098-9bebf9c3","signature_type":"Line"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/ntop/ndpi/commit/94e82c1de12323d992895830231865736a8abf2c","target":{"file":"src/lib/ndpi_serializer.c","function":"ndpi_json_string_escape"},"deprecated":false,"digest":{"function_hash":"124513550235448808411409595969741697594","length":1896},"id":"CVE-2026-86098-fff32fa4"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86098.json","vanir_signatures_modified":"2026-09-06T08:01:49Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"}]}