CVE-2026-13587

Source
https://cve.org/CVERecord?id=CVE-2026-13587
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13587.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-13587
Published
2026-06-29T16:00:11Z
Modified
2026-08-12T03:51:10Z
Severity
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
Details

A vulnerability was found in seladb PcapPlusPlus 25.05. The affected element is the function parse_by_block_type of the file light_pcapng.c of the component LightPcapNg Parser. Performing a manipulation of the argument captured_packet_length results in heap-based buffer overflow. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is described as difficult. The exploit has been made public and could be used.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13587.json"
}
References

Affected packages

Git / github.com/seladb/pcapplusplus

Affected ranges

Type
GIT
Repo
https://github.com/seladb/pcapplusplus
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "25.05"
        },
        {
            "last_affected": "25.05"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

25.*
25.05
v25.*
v25.05

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13587.json"