CVE-2026-54135
Deferred Deferred - Pending Action

Memory Exhaustion DoS in AirSane Scanner Server

Vulnerability report for CVE-2026-54135, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and directly passes this value to std::string::resize() without any upper-bound validation or safe parsing. An attacker can send an HTTP POST request with an artificially large Content-Length value. This forces the daemon to attempt allocating gigabytes of memory, resulting in a std::bad_alloc exception and immediately crashing the AirSane process. Additionally, providing non-numeric characters in the Content-Length header leads to undefined behavior (NaN to integer conversion) due to the lack of error handling during header parsing. Version 0.4.12 patches the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-30
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
airsane airsane to 0.4.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-54135 is a vulnerability in AirSane, a network scanning software, affecting versions before 0.4.12. It involves a flaw in the custom HTTP server where the Content-Length header is not properly validated. An attacker can send a POST request with an extremely large Content-Length value, causing the server to attempt allocating excessive memory. This leads to a memory exhaustion condition, crashing the AirSane process and resulting in a Denial of Service (DoS). Non-numeric characters in the header also cause undefined behavior due to lack of parsing validation.

The vulnerability is patched in version 0.4.12 by implementing a maximum request length limit and proper header validation to reject invalid or oversized requests.

Detection Guidance

To detect this vulnerability, monitor for crashes in the AirSane process or unusual memory usage spikes. Check HTTP server logs for POST requests with abnormally large Content-Length headers. Use network monitoring tools like tcpdump or Wireshark to inspect incoming HTTP traffic for malformed or excessively large Content-Length values.

Impact Analysis

This vulnerability allows remote unauthenticated attackers to crash the AirSane service by sending specially crafted HTTP requests. If exploited, it can disrupt scanning operations, cause service unavailability, and require manual intervention to restart the affected system. Users running vulnerable versions should update immediately to prevent potential downtime.

Compliance Impact

This vulnerability primarily impacts service availability by causing a DoS through memory exhaustion. While it does not directly expose or leak data, prolonged downtime could interfere with data processing workflows subject to GDPR or HIPAA, potentially leading to compliance violations if critical systems are unavailable.

Mitigation Strategies

Immediately upgrade AirSane to version 0.4.12 or later. If upgrading is not possible, restrict network access to the AirSane service or disable it until patched. Implement network-level protections like rate limiting or WAF rules to block requests with suspicious Content-Length headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54135. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart