PT-2026-27461 · Unknown+2 · Libvncserver+2

·

CVE-2026-32854

·

Published

2026-03-24

·

Updated

2026-06-23

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibVNCServer versions prior to the commit dc78dee LibVNCServer version 0.9.15
Description The software contains null pointer dereference issues in the HTTP proxy handlers within the httpProcessInput() function in httpd.c. These issues allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Specifically, missing validation of the strchr() return values in the CONNECT and GET proxy handling paths can trigger null pointer dereferences, leading to a server crash when httpd and proxy features are enabled.
Recommendations Update LibVNCServer to a version after the commit dc78dee.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32854
GHSA-XJP8-4QQV-5X4X
OESA-2026-2252
OESA-2026-2253
OESA-2026-2254
OESA-2026-2255
OPENSUSE-SU-2026:10433-1
OPENSUSE-SU-2026:20552-1
SUSE-SU-2026:1124-1
SUSE-SU-2026:1173-1
SUSE-SU-2026:1174-1
SUSE-SU-2026:21206-1
USN-8463-1

Affected Products

Libvncserver
Linuxmint
Ubuntu