CVE-2026-5067

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a bounded copy that does not guarantee NUL termination when the input length reaches the buffer size. During upgrade handling the buffer is copied to a local stack buffer and passed to strlen(); if no NUL exists in-bounds, strlen() reads beyond the stack buffer and subsequent concatenation with the WebSocket magic string can write out of bounds. This leads to out-of-bounds read and write on stack memory, resulting in crash (denial of service) and potentially code execution. The path is reachable when CONFIG_HTTP_SERVER_WEBSOCKET is enabled.
Configurations

Configuration 1 (hide)

cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Un atacante remoto no autenticado puede desencadenar corrupción de memoria en la ruta de actualización de WebSocket del servidor HTTP de Zephyr al enviar una cabecera Sec-WebSocket-Key manipulada. El analizador de cabeceras HTTP/1 copia la cabecera en un búfer de tamaño fijo utilizando una copia acotada que no garantiza la terminación NUL cuando la longitud de entrada alcanza el tamaño del búfer. Durante el manejo de la actualización, el búfer se copia a un búfer de pila local y se pasa a strlen(); si no existe un NUL dentro de los límites, strlen() lee más allá del búfer de pila y la concatenación subsiguiente con la cadena mágica de WebSocket puede escribir fuera de los límites. Esto conduce a lectura y escritura fuera de los límites en la memoria de pila, lo que resulta en un fallo (denegación de servicio) y potencialmente ejecución de código. La ruta es accesible cuando CONFIG_HTTP_SERVER_WEBSOCKET está habilitado.

08 Jul 2026, 13:27

Type Values Removed Values Added
CPE cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*
References () https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-wgr4-9pwq-94vj - () https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-wgr4-9pwq-94vj - Exploit, Patch, Vendor Advisory
First Time Zephyrproject zephyr
Zephyrproject

09 Jun 2026, 14:16

Type Values Removed Values Added
References () https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-wgr4-9pwq-94vj - () https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-wgr4-9pwq-94vj -

09 Jun 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 06:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-5067

Mitre link : CVE-2026-5067

CVE.ORG link : CVE-2026-5067


JSON object : View

Products Affected

zephyrproject

  • zephyr
CWE
CWE-170

Improper Null Termination

CWE-787

Out-of-bounds Write