CVE-2026-32854

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploit missing validation of strchr() return values in the CONNECT and GET proxy handling paths to trigger null pointer dereferences and crash the server when httpd and proxy features are enabled.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libvncserver_project:libvncserver:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:36

Type Values Removed Values Added
Summary
  • (es) Las versiones 0.9.15 y anteriores de LibVNCServer (corregido en el commit dc78dee) contienen vulnerabilidades de desreferencia de puntero nulo en los manejadores de proxy HTTP dentro de httpProcessInput() en httpd.c que permiten a atacantes remotos causar una denegación de servicio enviando solicitudes HTTP especialmente diseñadas. Los atacantes pueden explotar la falta de validación de los valores de retorno de strchr() en las rutas de manejo de proxy CONNECT y GET para desencadenar desreferencias de puntero nulo y bloquear el servidor cuando las características httpd y de proxy están habilitadas.

25 Mar 2026, 21:57

Type Values Removed Values Added
CPE cpe:2.3:a:libvncserver_project:libvncserver:*:*:*:*:*:*:*:*
First Time Libvncserver Project libvncserver
Libvncserver Project
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314 - () https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314 - Patch
References () https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x - () https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x - Exploit, Vendor Advisory
References () https://www.vulncheck.com/advisories/libvncserver-httpd-proxy-null-pointer-dereference - () https://www.vulncheck.com/advisories/libvncserver-httpd-proxy-null-pointer-dereference - Third Party Advisory

24 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 18:16

Updated : 2026-07-14 19:16


NVD link : CVE-2026-32854

Mitre link : CVE-2026-32854

CVE.ORG link : CVE-2026-32854


JSON object : View

Products Affected

libvncserver_project

  • libvncserver
CWE
CWE-476

NULL Pointer Dereference