CVE-2026-32854
LibVNCServer httpd proxy NULL Pointer Dereference
CVSS Score
0.0
EPSS Score
1.1%
EPSS Percentile
78th
LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploit missing validation of strchr() return values in the CONNECT and GET proxy handling paths to trigger null pointer dereferences and crash the server when httpd and proxy features are enabled.
| CWE | CWE-476 |
| Vendor | libvnc |
| Product | libvncserver |
| Published | Mar 24, 2026 |
| Last Updated | Mar 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for libvnc libvncserver
Be the first to know when new unknown vulnerabilities affecting libvnc libvncserver are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
LibVNC / LibVNCServer
0 ≤ 0.9.15
References
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.