Junglewise Threat Intelligence

CVE-2026-13587: seladb PcapPlusPlus heap overflow in LightPcapNg Parser

CVE-2026-13587 · Severity: low · CVSS 3.7 · Published 2026-06-29

Technologies: Seladb PcapPlusPlus. Vendors: Seladb.

Executive brief

PcapPlusPlus is a C++ library used for capturing and analyzing network traffic. A vulnerability in its packet parsing component could allow a remote attacker to cause a memory error by sending specially crafted network data. This could lead to a service crash or instability in applications using the library to process network files or live traffic.

Technical details

A heap-based buffer overflow (CWE-122) exists in the LightPcapNg Parser component of PcapPlusPlus version 25.05. The vulnerability is located in the 'parse_by_block_type' function within 'light_pcapng.c'. It is triggered by manipulating the 'captured_packet_length' argument during the parsing of Enhanced Packet Blocks (EPB). While the attack can be initiated remotely, it is characterized by high complexity and difficult exploitability. Successful exploitation primarily impacts service availability. A public proof-of-concept (PoC) has been disclosed.

Affected products

  • seladb PcapPlusPlus 25.05

Timeline

  • 2026-06-29: disclosed: Initial disclosure and NVD publication
  • 2026-06-29: advisory

References

Related threats