{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-54212",
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "state": "PUBLISHED",
        "assignerShortName": "NCSC.ch",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "datePublished": "2026-08-07T09:47:12.542Z",
        "dateUpdated": "2026-08-07T14:38:27.060Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "455daabc-a392-441d-aa46-37d35189897c",
                "shortName": "NCSC.ch",
                "dateUpdated": "2026-08-07T09:47:12.542Z"
            },
            "title": "TeamDavid: Buffer Overflow in JSON-parsing",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-787",
                            "description": "CWE-787 Out-of-bounds write",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Tobit Laboratories AG",
                    "product": "TeamDavid",
                    "modules": [
                        "Webbox"
                    ],
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThanOrEqual": "Rollout 524",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a \nbuffer overflow condition. By submitting a specially crafted JSON body, \nsuch as one that is at least 8 characters long and begins with a number,\n an unauthenticated attacker can cause the server to crash, resulting in\n denial of service. Depending on the stack state or if a stack canary \ncan be disclosed through another vulnerability, this buffer overflow \ncould potentially lead to remote code execution and full compromise of \nthe server. This issue affects TeamDavid through Rollout 524.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a \nbuffer overflow condition. By submitting a specially crafted JSON body, \nsuch as one that is at least 8 characters long and begins with a number,\n an unauthenticated attacker can cause the server to crash, resulting in\n denial of service. Depending on the stack state or if a stack canary \ncan be disclosed through another vulnerability, this buffer overflow \ncould potentially lead to remote code execution and full compromise of \nthe server.&nbsp;<span>This issue affects TeamDavid through Rollout 524.</span>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://david.tobit.software/releasenotes",
                    "tags": [
                        "release-notes"
                    ]
                },
                {
                    "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/",
                    "tags": [
                        "third-party-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "NETWORK",
                        "attackComplexity": "HIGH",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "HIGH",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "HIGH",
                        "vulnAvailabilityImpact": "HIGH",
                        "subAvailabilityImpact": "HIGH",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 9.5,
                        "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Lucas Dodgson of InfoGuard Labs",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.2"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-08-07T14:38:05.213025Z",
                                "id": "CVE-2026-54212",
                                "options": [
                                    {
                                        "Exploitation": "poc"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-07T14:38:27.060Z"
                }
            }
        ]
    }
}