CVE-2026-44756Critical RCE in EPP processing library
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
View on NVDAnalysis
A critical memory safety vulnerability in the Extended Passport Protocol (EPP) processing library allows unauthenticated attackers to execute arbitrary code via malformed network headers. Given the CVSS score of 10.0, systems using this library for identity or protocol processing are at immediate risk of full compromise.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-120EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.