{"apiVersion":"1.0","identifier":"CVE-2026-71979","description":"INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to crash the daemon by sending malformed XML with mismatched tags whose names exceed 1024 bytes. Attackers can send a single TCP packet on port 7624 with mismatched XML tags to trigger an unbounded sprintf() write into a fixed 1024-byte stack buffer in MsgQueue.cpp, terminating the daemon and disrupting all active client and driver sessions.","publishedAt":"2026-08-17T18:18:12","lastModifiedAt":"2026-08-17T20:16:46","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71979","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00482,"riskScore":0.78,"affectedProduct":"INDI","affectedVersions":"<=2.2.4.2","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-71979","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-71979","en":"https://www.redsauce.net/en/cves/CVE-2026-71979","fr":"https://www.redsauce.net/fr/cves/CVE-2026-71979","pt":"https://www.redsauce.net/pt/cves/CVE-2026-71979","de":"https://www.redsauce.net/de/cves/CVE-2026-71979","sk":"https://www.redsauce.net/sk/cves/CVE-2026-71979","el":"https://www.redsauce.net/el/cves/CVE-2026-71979"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-71979"}}