In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior.
| Software | From | Fixed in |
|---|---|---|
| eclipse / threadx_netx_duo | - | 6.4.4.202503 |