CVE-2026-18743CWE-131

CVE-2026-18743

Low · published September 1, 2026

CVSS v3.1
2.5
EPSS
0%
Percentile
2.5
In the wild
Unconfirmed
What it is

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

The record
Technical detail
CVSS v3.1
2.5 · LOW
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00124 · 2.5th percentile
Weakness
CWE-131 · Incorrect Calculation of Buffer Size
Published
2026-09-01T06:16Z
References (2)
EPSS history
Timeline
  • 02 SEP 03:34Z
    EPSS moved — → 0%
    epss
  • 01 SEP 00:57Z
    Popt-devel: popt-static: short realloc in poptconfigfiletostring
    cvelistv5