CVE-2026-102712

CVE-2026-102712 published: On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated peer drives an OOB source read of up to 25...

View full NVD advisory → ← Back to CVE watch