Heap-based buffer overflow in Gaia - CVE-2026-48135
Published: May 28, 2026
Gaia
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service, inject HTTP headers, or execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the HTTP request processing path when processing malformed HTTP requests. A remote attacker can send a specially crafted HTTP request to cause a denial of service, inject HTTP headers, or execute arbitrary code.
The issue affects HTTP-based services such as Mobile Access Portal and Identity Awareness Portals, except for Captive Portal.