THREAT OPS › Threat News › [NVD] CVE-2026-34956 (MEDIUM 5.9) — A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a cr
[NVD] CVE-2026-34956 (MEDIUM 5.9) — A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a cr
CVE-2026-34956 CVSS: 5.9 MEDIUM Published: 2026-05-05T16:16:11.927
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the
Indicators of compromise
- CVE-2026-34956cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-34956