{"id":"CVE-2026-106026","title":"tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches","summary":"tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename …","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-125"],"vendor":"H. Peter Anvin","product":"tftp-hpa","affected":["tftp-hpa >= 5.4 < 6.0"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T14:17:42.083","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106026","references":[{"url":"https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/","label":"disclosure@vulncheck.com"},{"url":"https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/commit/?id=6735086fb6475c3e1f1daf9829836b3d06f14291","label":"disclosure@vulncheck.com"},{"url":"https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/tree/tftpd/remap.c?h=tftp-hpa-5.4#n762","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/tftp-hpa-5.4-before-6.0-out-of-bounds-read-via-tftpd-remap-jump-rule","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T14:00:19.150Z","slug":"CVE-2026-106026","body":"## Overview\n\ntftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}