CVE-2026-86098 is a heap buffer overflow vulnerability in ntop nDPI versions before 6.0, specifically in the ndpi_json_string_escape function. This vulnerability allows attackers to trigger a heap corruption by supplying crafted network packet data, including TLS SNI, HTTP headers, or DNS names. The vulnerability has a CVSS score of 8.3 and is classified as HIGH severity.
CVE-2026-86091 is a high-severity vulnerability in ntopng, a network traffic monitoring tool. The vulnerability allows authenticated non-administrators to delete all host pools and member bindings, potentially bypassing security policies. This issue was published on 2026-09-04 and was last modified on 2026-09-23. Network administrators and security teams should assess their exposure and prioritize remedia [truncated]
CVE-2026-86090 is a high-severity vulnerability in ntopng, a network traffic monitoring tool. The vulnerability allows authenticated non-administrator users to delete all configured notification endpoints and recipients, effectively silencing all alerts. This issue was introduced due to a lack of authorization checks in the delete endpoints and recipients REST v2 handlers.
CVE-2026-38968 is a critical vulnerability in ntopng, a network traffic analyzer. The vulnerability is caused by the use of weak time-seeded pseudo-randomness during session creation, which can lead to predictable session identifiers and potentially allow for session hijacking. This could enable attackers to gain unauthorized access or control over monitored network traffic. Administrators and users of nt [truncated]
CVE-2017-5473 is a high-severity cross-site request forgery issue in ntopng through 2.4. According to NVD, a remote attacker could hijack the authentication of arbitrary users by inducing authenticated requests against administrative endpoints such as add-user, preference changes, user deletion, and password reset. The issue was publicly disclosed on 2017-01-14 and later marked modified by NVD on 2026-05-13.