Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2hc-xm25-6rh8

Опубликовано: 09 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.

EPSS

Процентиль: 39%
0.00177
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.

EPSS

Процентиль: 39%
0.00177
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-121