{"id":"CVE-2026-102728","title":"Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them","summary":"Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, bo…","severity":"none","cwe":["CWE-126"],"vendor":"Eclipse Foundation","product":"NetX Duo","affected":["netx_duo <= 6.5.1.202602"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T18:17:12.497","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102728","references":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-4q67-8385-j6m5","label":"emo@eclipse.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T18:42:35.818Z","slug":"CVE-2026-102728","body":"## Overview\n\nTwo client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}