CVE-2026-58058
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc)
CVSS
6.5
Medium
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Jun 28, 2026 · Last modified: Jun 30, 2026 · CWE-191
0.3%EPSS · 30 days0.3%
2026-06-302026-07-21
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.
- github.comhttps://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc
- github.comhttps://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83
- nmap.orghttps://nmap.org/changelog.html
- www.vulncheck.comhttps://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-480297.1 HIG—
———libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.6hCVE-2026-442516.5 MED23.4%
——7Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the manager, immediately disconnecting all agents from the manager. A second code path reached by the same underflow may allow heap memory corruption. This issue has been fixed in version 4.14.5.3dCVE-2026-409553.7 LOW10.2%
——3CVE-2026-40955 is an integer underflow
vulnerability in the traffic parsing function of Secure Access clients prior to
14.55. Attackers with intimate knowledge of and total control over the tunnel
protocol can create a non-persistent DoS against their client.6dCVE-2026-409543.7 LOW10.2%
——3CVE-2026-40954
is an integer underflow vulnerability in the traffic parsing function of Secure
Access clients prior to 14.55. Attackers with intimate knowledge of and total
control over the tunnel protocol can create a non-persistent DoS against their
client6dCVE-2026-482986.2 MED4.9%
——1CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.6dCVE-2026-482966.2 MED5.0%
——1CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.6d