High severity8.6NVD Advisory· Published Aug 5, 2026· Updated Aug 26, 2026
CVE-2026-71255
CVE-2026-71255
Description
nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the remaining PDU size (res_size_left) and is never validated against the caller-supplied buffers_length parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.23.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.