CVE-2026-16225: Davenardella SNAP7

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::NegotiatePDULength of the file src/core/s7_peer.cpp. The manipulation of the argument PDULength results in out-of-bounds write. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Affected products

  • Davenardella SNAP7: version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only

Published 2026-07-19. Last modified 2026-07-20.