By vendor

Nmap vulnerabilities

Known CVEs affecting Nmap products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-58058MEDIUM 6.5

    Nmap versions up to 7.99 contain a flaw in how they process IPv6 extension headers during network scanning. When a target or intermediary sends back a specially crafted IPv6 response with a truncated extension header, Nmap's pointer tracking can advance past the legitimate packet data. This causes the remaining-length counter to underflow—rolling over to an unexpectedly large number—leading to out-of-bounds memory reads and potential crashes. The issue is triggered specifically during raw IPv6 scans and requires no user interaction or authentication.