CVE-2026-22904

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.
Configurations

No configuration.

History

09 Feb 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 08:16

Updated : 2026-02-09 16:08


NVD link : CVE-2026-22904

Mitre link : CVE-2026-22904

CVE.ORG link : CVE-2026-22904


JSON object : View

Products Affected

No product.

CWE
CWE-121

Stack-based Buffer Overflow