PT-2026-91808 · Azure Linux · Ntopng

Published

2026-09-04

·

Updated

2026-09-04

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi json string escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-99945

Affected Products

Ntopng