PatchSiren

bacnet-stack CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH bacnet-stack CVE published 2026-06-04

CVE-2026-38570

CVE-2026-38570 is a HIGH-severity vulnerability in the bacnet_stack 1.3.1 library. The vulnerability is caused by an Out-of-bounds Read in the `bacnet_tag_number_decode` function, which can be exploited by attackers to cause a denial of service. The vulnerability has a CVSS score of 7.5 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-38570).