PT-2026-91808 · Azure Linux · Ntopng
Published
2026-09-04
·
Updated
2026-09-04
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi json string escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ntopng