Hi,
The following vulnerabilities were published for opennds.
CVE-2026-38819[0]:
| Multiple memory leaks in openNDS before 11.0.0 allow an
| unauthenticated attacker on the captive portal network to exhaust
| all available memory on the device within minutes.
Fixed by: https://github.com/openNDS/openNDS/commit/f2332e68c6d34f8403db346e380fff3817020d5c (v11.0.0)
Fixed by: https://github.com/openNDS/openNDS/commit/b2801d9f14af44a23be7e9a1c378623bc5947c4c (v11.0.0)
CVE-2026-38820[1]:
| openNDS before 11.0.0 is susceptible to unauthenticated OS command
| execution via shell command injection through the fas query
| parameter on the /opennds_preauth/ endpoint because of
| libopennds.sh.
Fixed by: https://github.com/openNDS/openNDS/commit/8c03750d9a17d601fa7bd03ae7cde20c7c8d1252 (v11.0.0)
CVE-2026-38821[2]:
| A heap-based buffer overflow vulnerability exists in openNDS before
| 11.0.0 that allows an unauthenticated attacker on the captive portal
| network to crash the openNDS daemon (denial of service) and
| potentially achieve remote code execution. This is in
| http_microhttpd.c.
Fixed by: https://github.com/openNDS/openNDS/commit/3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9 (v11.0.0)
CVE-2026-38822[3]:
| In openNDS before 11.0.0, the client_params.sh script, invoked by
| the openNDS daemon to serve the authenticated client status page, is
| vulnerable to OS command injection through crafted HTTP GET query
| parameter keys. An authenticated captive portal user can inject
| arbitrary shell commands by embedding semicolons in a URL query
| parameter name.
Fixed by: https://github.com/openNDS/openNDS/commit/294983e859bb678eef7db06fc9f6afab0b489d8e (v11.0.0)
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-38819
https://www.cve.org/CVERecord?id=CVE-2026-38819
[1] https://security-tracker.debian.org/tracker/CVE-2026-38820
https://www.cve.org/CVERecord?id=CVE-2026-38820
[2] https://security-tracker.debian.org/tracker/CVE-2026-38821
https://www.cve.org/CVERecord?id=CVE-2026-38821
[3] https://security-tracker.debian.org/tracker/CVE-2026-38822
https://www.cve.org/CVERecord?id=CVE-2026-38822
Please adjust the affected versions in the BTS as needed.