CVE-2026-62370 | KubeEdge up to 1.21.1/1.22.1/1.23.0 Viaduct pkg/viaduct/pkg/packer Reader.Read PayloadLen memory allocation

SecurityVulns

A vulnerability identified as critical has been detected in KubeEdge up to 1.21.1/1.22.1/1.23.0. This affects the function Reader.Read of the file pkg/viaduct/pkg/packer of the component Viaduct. The manipulation of the argument PayloadLen leads to uncontrolled memory allocation.

This vulnerability is traded as CVE-2026-62370. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More