SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-50103

MEDIUM · CVSS 6.5 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A NULL pointer dereference vulnerability exists in the L2 GOOSE and R-GOOSE shared parser, allowing network-adjacent attackers to crash applications that subscribe to GOOSE frames by sending specially crafted frames with malformed TLV values. This could disrupt services relying on these protocols, making it critical for organizations using affected products to prioritize mitigation efforts. Network administrators and security teams should assess their systems for exposure to this vulnerability to prevent potential service interruptions.

CVE
CVE-2026-50103
Severity
MEDIUM
CVSS
6.5
EPSS
0.17%

Original NVD Description

A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.