Description
An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption.
Published: 2026-10-08
Score: 7.1 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Brocade Fabric OS Web Management Daemon
First Time appeared Brocade
Brocade fabric Os
Weaknesses CWE-190
CWE-787
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption.
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T02:22:02.036Z

Reserved: 2026-09-08T22:51:12.166Z

Link: CVE-2026-87671

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:36.650

Modified: 2026-10-08T03:16:36.650

Link: CVE-2026-87671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T03:30:16Z

Weaknesses