CVE-2026-38819: Opennds
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.
Affected products
- Opennds Opennds: before 11.0.0 (fixed in 11.0.0)
Published 2026-08-28. Last modified 2026-09-09.