View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

ntop nDPI before 6.0 heap buffer overflow in ndpi_json_string_escape

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • YesWiki patches reflected XSS in Bazar widget id parameter (CVE-2026-52774)
    YesWiki has fixed a reflected XSS vulnerability (CVE-2026-52774) in its Bazar widget handler in version 4.6.6.

    • Affects YesWiki, a PHP-based wiki system, in all versions prior to 4.6.6 when the Bazar extension is enabled.
    • The Bazar widget handler reflects the id GET parameter into HTML attributes using only strip_tags(), which does not escape double quotes.
    • An attacker can break out of the attribute value, inject an event handler such as onmouseover, and execute arbitrary JavaScript in the victim's browser.
    • The flaw is reachable without authentication โ€” no login, page ownership, edit rights, or valid page tag is required; only the id parameter is needed.
    • Tracked as CVE-2026-52774 (CWE-80), rated Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N); fixed in YesWiki 4.6.6.
      ๐Ÿ“„ Source: github.com ยท ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • ntop nDPI before 6.0 heap buffer overflow in ndpi_json_string_escape (CVE-2026-86098)
    ntop nDPI versions before 6.0 contain a heap buffer overflow in the ndpi_json_string_escape function, tracked as CVE-2026-86098.

    • Affects ntop nDPI versions before 6.0, including the ndpi_serializer.c code at release 5.0
    • The ndpi_json_string_escape function performs unbounded writes beyond caller-supplied buffer boundaries, causing heap corruption (CWE-787 out-of-bounds write)
    • Attackers can trigger the overflow remotely with crafted network packet data such as TLS SNI, HTTP headers, or DNS names
    • CVSS 4.0 score 8.3 (High) with network vector, high attack complexity, and high integrity/availability impact; no privileges or user interaction required
    • Fixed in nDPI 6.0; finder credited to Tristan Madani, assigned by VulnCheck
      ๐Ÿ“„ Source: cve.threatint.com ยท ๐Ÿ“Ž Coverage: vulncheck.com ยท ๐Ÿ‘ via CVE ThreatInt
  • numbat - AI agent observability, (Fri, Sep 4th) โ€” SANS ISC

  • YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserial... โ€” CVE ThreatInt

  • YesWiki Authenticated SQL Injection in ReactionManagerYesWiki is a wiki syste... โ€” CVE ThreatInt

  • Reflected XSS via Unescaped Archived-Revision time Parameter in `handlers/p... โ€” CVE ThreatInt

  • YesWiki: Bazar form-field templates still apply |raw('html') to `field.labe... โ€” CVE ThreatInt

  • YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag... โ€” CVE ThreatInt

  • YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signatu... โ€” CVE ThreatInt

  • YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!open... โ€” CVE ThreatInt

  • YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}... โ€” CVE ThreatInt

  • YesWiki: SQL injection via the recentchanges action period argument leadi... โ€” CVE ThreatInt

  • YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code ... โ€” CVE ThreatInt

  • Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URLCam... โ€” CVE ThreatInt

  • PX4 Autopilot through 1.17.0 Null Pointer Dereference via param selectPX4 Aut... โ€” CVE ThreatInt

  • PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task ... โ€” CVE ThreatInt

  • Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attrib... โ€” CVE ThreatInt

  • CRLF injection in Laravel's default email rule enables SMTP smuggling and spo... โ€” CVE ThreatInt

  • Twig: Sandbox method allowlist bypass via Markup subclassTwig is a template... โ€” CVE ThreatInt

  • Laravel CRLF Injection in Email Validation (CVE-2026-48019) โ€” thehackerwire.com (discovered)

  • IXON VPN Client CRLF Injection Allows Root/SYSTEM Command Execution โ€” thehackerwire.com (discovered)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check