Unknown · Pcapplusplus · CVE-2026-13587
**Name of the Vulnerable Software and Affected Versions**
seladb PcapPlusPlus version 25.05
**Description**
A heap-based buffer overflow exists in the LightPcapNg Parser component within the `parse by block type()` function of the `light pcapng.c` file. This issue occurs when the `captured packet length` argument is manipulated, allowing a remote attacker to trigger the overflow. The attack is characterized by high complexity and difficult exploitability.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict the use of the `parse by block type()` function within the LightPcapNg Parser.