VYPR
High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026

CVE-2026-50254

CVE-2026-50254

Description

An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

2