{"id":"CVE-2026-75895","title":"In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.","summary":"In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-125"],"vendor":"Osmocom","product":"libsmpp34","affected":["libsmpp34 >= 1.10.0 < 1.14.5"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T19:17:10.243","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75895","references":[{"url":"https://cgit.osmocom.org/libsmpp34/commit/?id=af0e2912057551dab97bbe26e6a41f18a75f3bbb","label":"74b3a70d-cca6-4d34-9789-e83b222ae3be"}],"tags":["nvd","cve.org"],"epss":0.00156,"epssPercentile":0.05189,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-21T18:16:33.096334Z"},"ingestedAt":"2026-09-18T19:49:30.605Z","slug":"CVE-2026-75895","body":"## Overview\n\nIn libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208729,"id":"CVE-2026-75895","ts":1790016709154,"field":"cvss","old":null,"new":"7.5"},{"seq":208728,"id":"CVE-2026-75895","ts":1790016709154,"field":"severity","old":"none","new":"high"}]}