Heap-based Buffer Overflow Affecting pavel-odintsov/fastnetmon package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.02% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Heap-based Buffer Overflow vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-PAVELODINTSOVFASTNETMON-16963150
  • published28 May 2026
  • disclosed26 May 2026
  • creditUnknown

Introduced: 26 May 2026

New Malicious CVE-2026-48689  (opens in a new tab)
CWE-122  (opens in a new tab)

How to fix?

Avoid using pavel-odintsov/fastnetmon altogether.

Overview

Affected versions of this package are vulnerable to Heap-based Buffer Overflow through the incorrect bounds check in the dynamic_binary_buffer_t class methods, including append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, and memcpy_from_object_ptr. An attacker can execute arbitrary code or cause a denial of service by sending specially crafted network traffic (such as NetFlow, sFlow, IPFIX, or BGP messages) that triggers a write operation one byte past the end of a heap-allocated buffer.

CVSS Base Scores

version 4.0
version 3.1