CVE-2026-102728
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard.
| CWE | CWE-126 |
| Vendor | eclipse foundation |
| Product | netx duo |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation netx duo
Be the first to know when new unknown vulnerabilities affecting eclipse foundation netx duo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / NetX Duo
0 โค 6.5.1.202602
References
Credits
tinic