VDB
CVE-2026-19508
CVE-2026-19508
PUBLISHED
Reported by certcc · Published August 19, 2026
Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary code, via a crafted multipart/form-data request.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| RDK | RDK-B WebUI | rdkb-2025q4-kirkstone |
| RDK | RDK-B WebUI | rdkb-2025q4-kirkstone |
Timeline
- Aug 19, 2026 CVE Published
- Aug 22, 2026 Coalition ESS Score