CVE-2026-8275

LOW

bettercap zerogod IPP Service zerogod_ipp_primitives.go ippReadChunkedBody integer coercion

Title source: cna
STIX 2.1

Description

A vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnerability is the function ippReadChunkedBody of the file modules/zerogod/zerogod_ipp_primitives.go of the component zerogod IPP Service. Performing a manipulation results in integer coercion error. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is named 3731d5576cffae9eefe3721cd46a40933304129f. To fix this issue, it is recommended to deploy a patch.

References (8)

Core 8
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-362572 | bettercap zerogod IPP Service zerogod_ipp_primitives.go ippReadChunkedBody integer coercion
https://vuldb.com/vuln/362572
Signature, Permissions Required signature permissions-required
VDB-362572 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/362572/cti
Third Party Advisory third-party-advisory
Submit #811145 | bettercap <=v2.41.5 Integer Coercion Error
https://vuldb.com/submit/811145

Scores

CVSS v3 3.7
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-189 CWE-192
Status published
Products (7)
None/bettercap 2.41.0
None/bettercap 2.41.1
None/bettercap 2.41.2
None/bettercap 2.41.3
None/bettercap 2.41.4
None/bettercap 2.41.5
bettercap/bettercap 0 - 2.41.7Go
Published May 11, 2026
Tracked Since May 11, 2026