CVE-2026-41682

MEDIUM

pupnp: Port truncation via atoi() cast in parse_uri() allows SSRF port confusion

Title source: cna
STIX 2.1

Description

pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnerable to SRRF port confusion due to port truncation via atoi() cast in parse_uri(). This issue has been patched in version 1.18.5.

Scores

CVSS v4 6.9
EPSS 0.0004
EPSS Percentile 11.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-195 CWE-918
Status published
Products (1)
pupnp/pupnp < 1.18.5
Published May 08, 2026
Tracked Since May 09, 2026