Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-56123

8.1 · HIGH
Published Jun 25, 2026 dest-unreach CWE-122

Overview

CVE-2026-56123 is a high-severity vulnerability affecting dest-unreach socat. It was published on June 25, 2026 and has a CVSS 3.1 base score of 8.1 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.

Remediation

Check the references section for vendor advisories and patches from dest-unreach. Update socat to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
dest-unreach socat >= 1.8.0.0, < 1.8.1.2 Affected

Frequently Asked Questions

What is CVE-2026-56123?

CVE-2026-56123 is a high-severity vulnerability affecting dest-unreach socat. It was published on June 25, 2026 and has a CVSS 3.1 base score of 8.1 (HIGH).

How severe is CVE-2026-56123?

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2026-56123?

Check the references section for vendor advisories and patches from dest-unreach. Update socat to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-56123?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-56123 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.

Browse by year 2026