#1146882 ndpi: CVE-2026-86098

Package:
src:ndpi
Source:
src:ndpi
Submitter:
Salvatore Bonaccorso
Date:
2026-09-06 16:11:02 UTC
Severity:
normal
Tags:
#1146882#5
Date:
2026-09-06 16:09:16 UTC
From:
To:
Hi,

The following vulnerability was published for ndpi.

CVE-2026-86098[0]:
| ntop nDPI versions before 6.0 contain a heap buffer overflow
| vulnerability in the ndpi_json_string_escape function that writes
| beyond caller-supplied buffer boundaries. Attackers can trigger the
| overflow by supplying crafted network packet data including TLS SNI,
| HTTP headers, or DNS names that reach the vulnerable function,
| causing heap corruption.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86098
https://www.cve.org/CVERecord?id=CVE-2026-86098
[1] https://github.com/ntop/nDPI/commit/94e82c1de12323d992895830231865736a8abf2c

Regards,
Salvatore