Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-56099

OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 27.6%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2026-56099


Contact Us

Shodan ® - All rights reserved