CVE-2026-37539
Last modified
CVE-2026-37539 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted CAN FD frames.. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted CAN FD frames.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-37539?
How severe is CVE-2026-37539?
How do I fix CVE-2026-37539?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-37532AGL agl-service-can-low-level thru 17.1.12 contains a heap b…7.1
- CVE-2026-37534Integer underflow vulnerability in Open-SAE-J1939 thru commi…9.8
- CVE-2026-37535openxc/isotp-c thru commit 5a5d19245f65189202719321facd49ce6…7.1
- CVE-2026-37536miaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7…8.8
- CVE-2026-37537collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce4…8.1
- CVE-2026-37538Buffer overflow vulnerability in socketcand 0.4.2 in file so…7.5
- CVE-2026-3754A vulnerability was found in SourceCodester Sales and Invent…8.8
- CVE-2026-37540OpenAMP v2025.10.0 ELF loader contains an integer overflow v…9.8
- CVE-2026-37541Buffer overflow vulnerability in Open Vehicle Monitoring Sys…10
- CVE-2026-3755A vulnerability was determined in SourceCodester Sales and I…8.8
- CVE-2026-37552Unsafe deserialization vulnerability in MixPHP Framework 2.x…8.4
- CVE-2026-37554An issue was discovered in Vanetza V2X v26.02 allowing remot…7.5
Are you affected by CVE-2026-37539?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
