๐Ÿ” CVE Alert

CVE-2026-71979

HIGH 7.5

INDI indiserver 2.2.4.2 Stack Buffer Overflow via XML Tag Parsing

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to crash the daemon by sending malformed XML with mismatched tags whose names exceed 1024 bytes. Attackers can send a single TCP packet on port 7624 with mismatched XML tags to trigger an unbounded sprintf() write into a fixed 1024-byte stack buffer in MsgQueue.cpp, terminating the daemon and disrupting all active client and driver sessions.

CWE CWE-121
Vendor indilib
Product indi
Published Aug 17, 2026
Last Updated Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for indilib indi

Be the first to know when new high vulnerabilities affecting indilib indi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

indilib / indi
0 โ‰ค 2.2.4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/indilib/indi/issues/2472 github.com: https://github.com/indilib/indi/commit/96bbd7f564bbb128a129019e44eadd40dd49cff9 vulncheck.com: https://www.vulncheck.com/advisories/indi-indiserver-stack-buffer-overflow-via-xml-tag-parsing

Credits

Fatullayev Asadbek