B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

[Critical] CVE-2026-5067 – A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTT...

Critical CVE-2026-5067 A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a bounded copy that does not guarantee NUL...

Original-Artikel öffnen Zurück zur Übersicht