SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-15813

MEDIUM · CVSS 6.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The network packet de-fragmentation engine in kronosnet versions up to 1.34 is vulnerable due to improper validation of sequence numbers in incoming payload fragments. This flaw can be exploited by an attacker to send malformed packets, potentially leading to out-of-bounds memory access or heap corruption, which may cause application crashes or system instability. Organizations using affected versions should prioritize patching this vulnerability to mitigate risks of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15813
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%

Original NVD Description

A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability.