Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-26456

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 commit 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 中的 ccoap 服务器端会话管理逻辑中存在一个空指针解引用漏洞。该问题源于请求分发线程与会话清理线程在访问共享会话列表节点时,由于缺乏适当的同步机制,导致了竞态条件。

AI Predicted 5.6 Difficulty: Hard

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-26456

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition between the request dispatch thread and the session cleanup thread when accessing shared session list nodes without proper synchronization.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-26456

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-26456

登录查看更多情报信息。

Proof of Concept for CVE-2026-26456 (1)

Other References for CVE-2026-26456 (1)

Same Patch Batch · n/a · 2026-08-27 · 49 CVEs total

CVE-2026-37006 gpt-researcher v0.14.7之前WebSocket端点RCE漏洞
CVE-2026-37070 Veno 4.4.9 文件管理器访问控制不当
CVE-2026-37064 Veno File Manager 4.4.9 未认证用户枚举漏洞
CVE-2026-37198 Open5GS v2.7.6 SMF组件整数溢出致服务拒绝
CVE-2026-37068 VFM 4.4.9 认证用户任意文件写入
CVE-2026-37072 Veno文件管理器4.4.9访问控制不当
CVE-2026-37069 Veno File Manager 4.4.9 绝对路径泄露漏洞
CVE-2026-30612 Time4Popcorn 多平台更新器远程代码执行漏洞
CVE-2026-37007 crewai-tools 1.10.2rc1 路径遍历致代码执行
CVE-2026-37009 crewai-tools 1.10.2rc1 SQL注入漏洞
CVE-2026-37073 Veno File Manager 4.4.9访问控制缺陷致邮件发送
CVE-2026-37066 Veno File Manager 4.4.9 路径遍历致任意文件读取漏洞
CVE-2026-37071 Veno File Manager 4.4.9 任意文件重命名致权限提升
CVE-2026-37065 Veno File Manager 4.4.9 任意文件删除
CVE-2026-37012 PentestGPT 1.0.0 Langfuse 硬编码密钥致数据泄露
CVE-2026-35868 LB-link AC2100_AZ3 V1.0.4 命令注入漏洞
CVE-2026-35869 LB-link AC450M V4.0.0 命令注入漏洞
CVE-2026-36102 Checkmate 3.3.0 邀请接口越权提权
CVE-2026-30070 free5gc v4.0.1 HandleGetSharedData拒绝服务漏洞
CVE-2026-30069 free5gc v4.0.1 UDMC空指针解引用致DoS

Showing top 20 of 49 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-26456

No comments yet


Leave a comment