An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.
References
Configurations
No configuration.
History
30 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 22:16
Updated : 2026-07-01 18:17
NVD link : CVE-2026-50254
Mitre link : CVE-2026-50254
CVE.ORG link : CVE-2026-50254
JSON object : View
Products Affected
No product.
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
