{
    "id": "CVE-2026-58058",
    "published": "2026-06-28 02:16:33",
    "last_modified": "2026-06-30 17:31:44",
    "cvss_score": "6.5",
    "cvss_severity": "MEDIUM",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
    "cwe": "CWE-191",
    "description": "Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.",
    "epss_score": "0.01454",
    "epss_percentile": "0.72710",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-10 18:17:54",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "nmap",
            "product": "nmap"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "52647",
            "title": "Nmap  7.99  - Extension Header Integer Underflow",
            "date": "2026-08-17",
            "url": "https://www.exploit-db.com/exploits/52647"
        }
    ],
    "refs_list": [
        "https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc",
        "https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83",
        "https://nmap.org/changelog.html",
        "https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing"
    ]
}