By vendor
Nmap vulnerabilities
Known CVEs affecting Nmap products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-58058MEDIUM 6.5
Nmap versions up to 7.99 contain a flaw in how they process IPv6 extension headers during network scanning. When a target or intermediary sends back a specially crafted IPv6 response with a truncated extension header, Nmap's pointer tracking can advance past the legitimate packet data. This causes the remaining-length counter to underflow—rolling over to an unexpectedly large number—leading to out-of-bounds memory reads and potential crashes. The issue is triggered specifically during raw IPv6 scans and requires no user interaction or authentication.