← العودة للجدول
CVE-2026-5067
CVE-2026-5067 — A remote, unauthenticated attacker can trigger memory corruption in Zephyr'
📅 2026-06-09
🔴 Critical 🔥 No NVD Exploit Exploit CVSS 9.8

📋 الوصف الكامل

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a bounded copy that does not guarantee NUL termination when the input length reaches the buffer size. During upgrade handling the buffer is copied to a local stac

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-5067

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-5067 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←