Hi, The following vulnerability was published for ndpi. CVE-2026-88357[0]: | nDPI 5.1.0 contains a memory access issue in the DNS dissector and | serializer deserialization code. Specially crafted network input can | cause byte-buffer addresses at odd offsets to be cast to uint16_t or | wider integer pointers and directly dereferenced without alignment | checks. This results in undefined behavior and can cause process | termination in UBSan-instrumented builds or on strict-alignment | architectures, leading to denial of service. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-88357 https://www.cve.org/CVERecord?id=CVE-2026-88357 [1] https://github.com/ntop/nDPI/issues/3213 [2] https://github.com/ntop/nDPI/pull/3231 Please adjust the affected versions in the BTS as needed. Regards, Salvatore