CVE-2026-50254

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
30/06/2026
Last modified:
01/07/2026

Description

An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.