{"apiVersion":"1.0","identifier":"CVE-2026-44254","description":"Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMessage() in src/remoted/secure.c passes a pointer inside its stack buffer to ReadSecMSG(), and src/os_crypto/shared/msgs.c decompresses up to OS_MAXSTR bytes at that offset. For an encrypted agent message on TCP port 1514 that expands to 65,536 bytes, os_zlib_uncompress() writes a terminating null byte beyond the end of the destination buffer. The resulting stack out-of-bounds write in the root-level remoted daemon can crash message processing and disrupt agent communications. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.","publishedAt":"2026-08-19T16:17:10","lastModifiedAt":"2026-08-19T19:17:16","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-44254","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00355,"riskScore":0.55,"affectedProduct":"Wazuh","affectedVersions":">=1.0.0,<4.14.6,>=5.0.0-beta2,<5.0.0-beta2","vulnerabilityType":"Critical software","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-44254","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-44254","en":"https://www.redsauce.net/en/cves/CVE-2026-44254","fr":"https://www.redsauce.net/fr/cves/CVE-2026-44254","pt":"https://www.redsauce.net/pt/cves/CVE-2026-44254","de":"https://www.redsauce.net/de/cves/CVE-2026-44254","sk":"https://www.redsauce.net/sk/cves/CVE-2026-44254","el":"https://www.redsauce.net/el/cves/CVE-2026-44254"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-44254"}}