CVE-2026-5720Disclosure(miniupnp_project / miniupnpd)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the allocated HTTP request buffer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-191

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • miniupnpd

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
miniupnpd

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-18: 2Technical Details · 2026-04-18: 204-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5720 miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure b… https://www.cve.org/CVERecord?id=CVE-2026-5720

    Post summary

    The CVE-2026-5720 entry describes an integer underflow in miniupnpd’s SOAPAction header parsing that could lead to denial of service or information disclosure, with no exploit, PoC, or patch information provided.

    00000119
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5720 Integer Underflow in miniupnpd SOAPAction Header Parsing Causes Denial of Service https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5720

    Post summary

    The CVE‑2026‑5720 vulnerability is an integer underflow in miniupnpd’s SOAPAction header parsing, resulting in a denial‑of‑service condition.

    0000039
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appminiupnp_projectminiupnpd---

Explore more