CVE-2026-1301

Publication date

2026-02-05 19:09:37

Family

icscert

State

PUBLISHED

Description

In builds with PubSub and JSON enabled, a crafted JSON message can cause the decoder to write beyond a heap-allocated array before authentication, reliably crashing the process and corrupting memory.