← Back to CVE List
Vulnerability Intelligence Report
tftp-hpa 5.4 before 6.0 Out-of-Bounds Read via tftpd Remap Jump Rule

CVE-2026-106026

tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.

No Active Exploit Signals
CVSS Base Score
6.3
MEDIUM
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-125 ↗Out-of-bounds Read

Affected Products & Versions

Vendor Product Affected Versions
H. Peter Anvin tftp-hpa 5.4 < 6.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-10-06T13:13:19
Published2026-10-06T13:35:48
Patch Date2026-08-23
Last Updated2026-10-06T17:15:34

LINK COPIED TO CLIPBOARD