Description
miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the allocated HTTP request buffer.
INFO
Published Date :
2026-04-17T21:39:54.818Z
Last Modified :
2026-04-20T16:59:21.060Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2026-5720 vulnerability.
| Vendors | Products |
|---|---|
| Miniupnp Project |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-5720.