CVE-2026-106026: H. Peter Anvin Tftp-Hpa

Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.

tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.

Affected products

Published 2026-10-06. Last modified 2026-10-06.