miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the allocated HTTP request buffer.
References
| Link | Resource |
|---|---|
| https://github.com/miniupnp/miniupnp/ | Product |
| https://github.com/miniupnp/miniupnp/commit/f56bd09b2f2650126b832c5f30a65a09e28167fa | Patch |
| https://www.vulncheck.com/advisories/miniupnpd-integer-underflow-soapaction-header-parsing | Third Party Advisory VDB Entry |
Configurations
History
11 May 2026, 20:05
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:miniupnp_project:miniupnpd:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| First Time |
Miniupnp Project
Miniupnp Project miniupnpd |
|
| References | () https://github.com/miniupnp/miniupnp/ - Product | |
| References | () https://github.com/miniupnp/miniupnp/commit/f56bd09b2f2650126b832c5f30a65a09e28167fa - Patch | |
| References | () https://www.vulncheck.com/advisories/miniupnpd-integer-underflow-soapaction-header-parsing - Third Party Advisory, VDB Entry |
04 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
20 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
17 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-17 22:16
Updated : 2026-06-29 14:22
NVD link : CVE-2026-5720
Mitre link : CVE-2026-5720
CVE.ORG link : CVE-2026-5720
JSON object : View
Products Affected
miniupnp_project
- miniupnpd
