CVE-2026-32854 identifies null pointer dereference vulnerabilities in LibVNCServer versions 0.9.15 and prior, affecting its HTTP proxy handlers. Remote attackers can exploit missing validation of strchr() return values in CONNECT and GET proxy paths to trigger a server crash, resulting in a denial of service. This vulnerability has a CVSS score of 7.5 HIGH, indicating it can be exploited remotely with low complexity and no privileges or user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.15CPE matchmatch criteria | cpe:2.3:a:libvncserver_project:libvncserver:*:*:*:*:*:*:*:* | ||
>= 0, <= 0.9.15CPE match | cpe:2.3:a:libvnc_project:libvncserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.