🔐 CVE Alert

CVE-2026-32854

UNKNOWN 0.0

LibVNCServer httpd proxy NULL Pointer Dereference

CVSS Score
0.0
EPSS Score
1.1%
EPSS Percentile
78th

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploit missing validation of strchr() return values in the CONNECT and GET proxy handling paths to trigger null pointer dereferences and crash the server when httpd and proxy features are enabled.

CWE CWE-476
Vendor libvnc
Product libvncserver
Published Mar 24, 2026
Last Updated Mar 27, 2026
Stay Ahead of the Next One

Get instant alerts for libvnc libvncserver

Be the first to know when new unknown vulnerabilities affecting libvnc libvncserver are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

LibVNC / LibVNCServer
0 ≤ 0.9.15

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x github.com: https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314 vulncheck.com: https://www.vulncheck.com/advisories/libvncserver-httpd-proxy-null-pointer-dereference

Credits

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.