Signed to Unsigned Conversion Error Affecting pupnp package, versions <1:1.14.31-1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.35% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-PUPNP-16306984
  • published27 Apr 2026
  • disclosed8 May 2026

Introduced: 27 Apr 2026

CVE-2026-41682  (opens in a new tab)
CWE-195  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade Debian:unstable pupnp to version 1:1.14.31-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream pupnp package and not the pupnp package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnerable to SRRF port confusion due to port truncation via atoi() cast in parse_uri(). This issue has been patched in version 1.18.5.