THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-34956 (MEDIUM 5.9) — A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a cr

[NVD] CVE-2026-34956 (MEDIUM 5.9) — A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a cr

lownvdPublished 2026-05-05

CVE-2026-34956 CVSS: 5.9 MEDIUM Published: 2026-05-05T16:16:11.927

A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-34956