THREATOPS
THREAT OPSThreat News › Escargot v4.3.0-214-gfaee4437 Debugger WebSocket Off-by-One Stack Buffer Overflow

Escargot v4.3.0-214-gfaee4437 Debugger WebSocket Off-by-One Stack Buffer Overflow

lowfulldisclosurePublished 2026-08-26

<p>Posted by Ron E on Aug 26</p>Escargot contains a remotely triggerable one-byte stack-based out-of-bounds<br /> write in the WebSocket message handling logic used by the debugger.<br /> <br /> When Escargot::DebuggerTcp::receive() receives a binary WebSocket payload<br /> that completely fills the caller-provided stack buffer, the function<br /> successfully copies the payload into the available

Original source: https://seclists.org/fulldisclosure/2026/Aug/107