Executive brief
A vulnerability in a Check Point HTTP-based service allows the system to incorrectly process specially crafted web requests. This could lead to service instability or a partial denial of service, potentially disrupting network traffic or administrative access. No sensitive customer data is reported to be at risk from this specific issue.
Technical details
This vulnerability is classified as a heap-based buffer overflow (CWE-122) within a Check Point HTTP-based service. The root cause is a failure to properly parse and validate malformed HTTP requests. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP packets over the network. Successful exploitation primarily impacts availability, potentially causing the service to crash or become unresponsive. Check Point has released advisory sk184991 to address the issue.
Affected products
- Check Point HTTP-based service
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory