Description
AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and directly passes this value to std::string::resize() without any upper-bound validation or safe parsing. An attacker can send an HTTP POST request with an artificially large Content-Length value. This forces the daemon to attempt allocating gigabytes of memory, resulting in a std::bad_alloc exception and immediately crashing the AirSane process. Additionally, providing non-numeric characters in the Content-Length header leads to undefined behavior (NaN to integer conversion) due to the lack of error handling during header parsing. Version 0.4.12 patches the issue.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A remote unauthenticated attacker can exploit AirSane by sending a crafted HTTP POST request containing an excessively large or malformed Content-Length header. The daemon’s custom HTTP server processes this unvalidated value directly in std::string::resize(), causing an allocation attempt for gigabytes of memory and resulting in a std::bad_alloc exception that crashes the service. The flaw also produces undefined behavior when non‑numeric characters appear in the header, but the impact remains limited to memory exhaustion and denial of service; it does not compromise confidentiality or integrity.

Affected Systems

The vulnerability affects all SimulPiscator AirSane installations running a version earlier than 0.4.12. The patch that validates the Content‑Length header and adds error handling was introduced in the 0.4.12 release, so any instance of AirSane prior to that version is susceptible.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate‑to‑high risk, while the EPSS score of less than 1% suggests that real‑world exploitation is low but not impossible. AirSane is an unprivileged service exposed over HTTP, so an attacker can reach it from any networked location without authentication; the low barrier to access increases the likelihood of an attempted exploit. Because the flaw manifests as a denial of service through memory exhaustion, an attacker can disrupt service availability, potentially affecting connected scanning workflows, but cannot achieve code execution or data exposure. The vulnerability is not listed in CISA’s KEV catalog, meaning no widespread, documented exploitation has been observed as of the current reporting.

Generated by OpenCVE AI on September 15, 2026 at 22:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to AirSane version 0.4.12 or higher to apply the Content‑Length validation fix.
  • If an upgrade cannot be performed immediately, isolate the AirSane daemon by configuring firewall rules that allow traffic only from trusted IP addresses.
  • After upgrading or configuring the firewall, restart the AirSane service to load the updated binary and enforce the new resource limits.

Generated by OpenCVE AI on September 15, 2026 at 22:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Simulpiscator
Simulpiscator airsane
Vendors & Products Simulpiscator
Simulpiscator airsane

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and directly passes this value to std::string::resize() without any upper-bound validation or safe parsing. An attacker can send an HTTP POST request with an artificially large Content-Length value. This forces the daemon to attempt allocating gigabytes of memory, resulting in a std::bad_alloc exception and immediately crashing the AirSane process. Additionally, providing non-numeric characters in the Content-Length header leads to undefined behavior (NaN to integer conversion) due to the lack of error handling during header parsing. Version 0.4.12 patches the issue.
Title AirSane has a Remote Denial of Service (OOM) via Unvalidated Content-Length in HTTP Server
Weaknesses CWE-400
CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Simulpiscator Airsane
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:47:55.523Z

Reserved: 2026-06-11T21:15:33.870Z

Link: CVE-2026-54135

cve-icon Vulnrichment

Updated: 2026-09-14T18:47:49.048Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T20:17:14.330

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:15:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling