Vulnerability Intelligence Report
tftp-hpa 5.4 before 6.0 Out-of-Bounds Read via tftpd Remap Jump Rule
CVE-2026-106026
tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.
No Active Exploit Signals
CVSS Base Score
6.3
MEDIUM
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-125 ↗Out-of-bounds Read
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| H. Peter Anvin | tftp-hpa | 5.4 < 6.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-10-06T13:13:19 |
| Published | 2026-10-06T13:35:48 |
| Patch Date | 2026-08-23 |
| Last Updated | 2026-10-06T17:15:34 |
Community Chatter & Buzz