
CVE-2026-40170: ngtcp2: ngtcp2_qlog_parameters_set_transport_params() stack buffer overflow https://www.openwall.com/lists/oss-security/2026/04/17/12 serializes transport parameters into a fixed stack buffer (uint8_t buf[1024]) without complete bounds checks
Post summary
The post discloses a stack buffer overflow in ngtcp2, providing technical details but no PoC, exploit, or patch information.


