CVE-2026-50103
A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-228
- Published
- 2026-07-23
- Last modified
- 2026-07-24
Affected products
- MZ Automation libIEC61850
Weakness type
Related vulnerabilities
- CVE-2025-59174 — Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an...
- CVE-2026-25657 — Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2026-42100 — DoS in Sparx Pro Cloud Server
- CVE-2026-34232 — Firebird: DoS via `op_response` packet from client
- CVE-2024-53828 — Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2026-20125 — A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release...
- CVE-2025-2529 — IBM Terracotta denial of service
- CVE-2025-47736 — dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash...