CVE-2026-54412
LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response f
CVSS
8.2
Alto
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Publicado: 14 jun 2026 · Última mod.: 10 ago 2026 · CWE-125 · CWE-191
0.4%EPSS · 30 días0.4%
2026-08-262026-09-23
LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - to crash a subscribed MQTT-C client and potentially disclose adjacent heap memory by sending a single crafted PUBLISH packet.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-816455.9 MED—
———Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.53mCVE-2026-965462.5 BAJ—
——0A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.13hCVE-2026-965454.4 MED—
——0An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the larger RGBA row size. This can copy adjacent heap contents into the decoded image and may crash the plug-in.12hCVE-2026-888405.3 MED—
——0BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.12hCVE-2026-888356.1 MED—
——0BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.12hCVE-2026-79616—4.6%
——1Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.17h