SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81334

MEDIUM · CVSS 6.1 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability arises from the Darknet framework's failure to validate an index derived from a configuration file against the length of its layer array, leading to potential out-of-bounds memory access. This flaw allows an attacker to craft a malicious configuration file that can cause a crash or enable arbitrary memory writes, which could compromise the integrity of the application. Organizations utilizing Darknet for machine learning or neural network applications should prioritize addressing this vulnerability to mitigate risks associated with unauthorized memory manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81334
Severity
MEDIUM
CVSS
6.1
EPSS
0.13%

Original NVD Description

darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's length. The array is allocated in src-lib/darknet_network.cpp as xcalloc(net.n, sizeof(Darknet::Layer)), sized to exactly the number of layer sections the file declares. The shortcut, scale_channels and sam sections supply that index through their from field and the route section through its layers field, and parse_shortcut_section in src-lib/darknet_cfg.cpp reads net.layers[index].outputs with no bounds check, which reads past the allocation. The dispatch loop in create_network then reuses the same index to assign net.layers[l.index].use_bin_output and net.layers[l.index].keep_delta_gpu, writing past the allocation at an offset the file controls, with a fixed one-byte value. Parsing a crafted configuration file is sufficient: the parse runs before any weights file is opened and needs no non-default option, so the result is a reliable crash and a write whose location, though not its value, is chosen by whoever supplied the file.