CVE-2026-56123Dest-unreach · Socat
Vulnerability data via NVD (ingested)
socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-56123product:"Dest-unreach Socat"http.html:"Socat"More intel sources (5)
vuln:CVE-2026-56123vulnerabilities.cve_id: CVE-2026-56123CVE-2026-56123CVE-2026-56123"CVE-2026-56123" exploit -site:nvd.nist.gov