CVE-2026-38821

Source
https://cve.org/CVERecord?id=CVE-2026-38821
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-38821.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-38821
Downstream
Published
2026-08-28T00:10:10.769Z
Modified
2026-08-29T14:12:53.194440Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L CVSS Calculator
Summary
[none]
Details

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/38xxx/CVE-2026-38821.json",
    "cwe_ids": [
        "CWE-122"
    ],
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/opennds/opennds

Affected ranges

Type
GIT
Repo
https://github.com/opennds/opennds
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "11.0.0"
        }
    ]
}

Affected versions

v10.*
v10.1.0
v10.1.1
v10.1.2
v10.1.3
v10.2.0
v10.3.0
v10.3.1
v5.*
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v6.*
v6.0.0
v7.*
v7.0.0
v7.0.1
v8.*
v8.0.0
v8.1.0
v8.1.1
v9.*
v9.0.0
v9.1.0
v9.1.1
v9.10.0
v9.2.0
v9.3.0
v9.4.0
v9.5.0
v9.5.1
v9.6.0
v9.7.0
v9.8.0
v9.9.0
v9.9.1

Database specific

vanir_signatures
[
    {
        "id": "CVE-2026-38821-1031677f",
        "target": {
            "function": "redirect_to_splashpage",
            "file": "src/http_microhttpd.c"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "311421305056004275875715927435170307547",
            "length": 1446.0
        },
        "signature_version": "v1",
        "source": "https://github.com/opennds/opennds/commit/3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-38821-a6253985",
        "target": {
            "file": "src/http_microhttpd.c"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "104120432630675651287375848698660759807",
                "333119376069059100285092984272616262566",
                "77823246634169758154534252860526279576",
                "195099720023997218876787609873204965919"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/opennds/opennds/commit/3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9",
        "signature_type": "Line"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-38821.json"
vanir_signatures_modified
"2026-08-29T14:12:53Z"