
#CVE-2026-7840 - #UltraVNC Repeater HTTP Global Buffer Overflow | Attribute | Value | |-----------|-------| | **CVE** | CVE-2026-7840 | | **CVSS** | 9.8 Critical (CVSS 3.1) | | **CWE** | CWE-121 — Stack-based Buffer Overflow | | **Vendor** | UltraVNC (UVNC BVBA) | | **Product** | UltraVNC Repeater | | **Affected** | <= 1.8.2.2 | | **Component** | `repeater/webgui/webutils.c` — `wi_senderr()`, `wi_replyhdr()` | | **Root Cause** | Unchecked `sprintf()` into 1000-byte global buffer `hdrbuf` | | **Trigger** | HTTP GET with URI length > 1000 bytes | | **Auth** | None — pre-authentication | #0days #exploit #cybersecurity #hacking #security #CVS #RCE #antisec #infosec
Post summary
The post announces a critical buffer overflow vulnerability in UltraVNC Repeater, detailing its technical aspects without referencing code, patches, or active exploits.


