CVE-2026-50103: Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
Published Jul 23, 2026
·Updated
A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.
Affected Software
1 affected component
MZ Automation LibIEC61850
Event History
Jul 23, 2026
CVE Published
via MITRE·08:50 PM
Data Sourced
via MITRE·08:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-50103?
The severity of CVE-2026-50103 is medium with a score of 6.5.
2
How do I fix CVE-2026-50103?
To fix CVE-2026-50103, ensure that you update the MZ Automation LibIEC61850 to the latest version provided by the vendor.
3
What type of vulnerability is CVE-2026-50103?
CVE-2026-50103 is classified as a null pointer dereference vulnerability.
4
What impact can CVE-2026-50103 have on my application?
CVE-2026-50103 can allow a network-adjacent attacker to crash a subscribing application.
5
Who is affected by CVE-2026-50103?
Any user of MZ Automation LibIEC61850 may be affected by CVE-2026-50103.