CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-56123

highCVSS 8.1covered by 2 sourcesfirst seen 2026-06-09
It was discovered that socat incorrectly handled the SOCKS5 proxy server reply parser. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-56123) It was discovered that socat incorrectly handled a sample script. A local attacker could possibly use this issue to overwrite arbitrary files. This issue only affected Ubuntu 24.04 LTS. (CVE-2024-54661)

CSIRTS triage

What
A heap buffer overflow vulnerability exists in the SOCKS5 Reply Parser.
Who is affected
Deployments of socat versions between 1.8.0.0 and 1.8.1.1.
Urgency
Remediation is urgent due to the high severity and potential for exploitation.
Action
Upgrade socat to a version beyond 1.8.1.1 to mitigate this vulnerability.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-56123

Get an email if CVE-2026-56123 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-56123

CVE.org record

Embed the live status

CVE-2026-56123 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-56123 status](https://www.csirts.com/badge/CVE-2026-56123)](https://www.csirts.com/cve/CVE-2026-56123)