# CVE-2026-38819

## Summary

- **CVE ID:** CVE-2026-38819
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-401
- **Published:** Aug 28, 2026
- **Last Modified:** Aug 28, 2026

## Description

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

## Affected Products

- openNDS — openNDS (0)

## References

- [CNA](https://github.com/openNDS/openNDS/commit/f2332e68c6d34f8403db346e380fff3817020d5c)
- [CNA](https://github.com/openNDS/openNDS/commit/b2801d9f14af44a23be7e9a1c378623bc5947c4c)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._