rootpwn

critical · CVSS v3 9.8 · CVSS v4 8.6 · EPSS 0.00313

CVE-2026-97152

Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport…

Description

Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.

Scores

Severity
critical
CVSS v2
7.5
CVSS v3
9.8
CVSS v4
8.6
EPSS
0.00313

← All CVEs