Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder — CVE-2026-11105 PoC demonstrating a stack buffer overflow in a custom Base64 decoder; crafted oversized input overwrites stack memory and enables arbitrary code execution. | Kitploit
Tools/GitHubGitHub/george0papasotiriou/cve-2026-11105-stack-buffer-overflow-in-custom-base64-decoder
Vulnerability AnalysisExploitationLearning & EducationPayload DevelopmentBinary Exploitation
GitHubgeorge0papasotiriou/cve-2026-11105-stack-buffer-overflow-in-custom-base64-decoder

CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder

CVE-2026-11105 PoC demonstrating a stack buffer overflow in a custom Base64 decoder; crafted oversized input overwrites stack memory and enables arbitrary code execution.

View Repository
131 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-11105 – Stack Buffer Overflow in Custom Base64 Decoder

Program Code (C)

// base64_vuln.c - Vulnerable Base64 decoder
#include <stdio.h>
#include <string.h>
#include <stdint.h>

int base64_decode(const char *in, size_t inlen, char *out, size_t outlen) {
    static const char table[] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
    int outpos = 0;
    for (int i=0; i<inlen; i+=4) {
        uint32_t sextet = 0;
        int bytes = 0;
        for (int j=0; j<4; j++) {
            if (i+j >= inlen) break;
            const char *p = strchr(table, in[i+j]);
            if (p) sextet = (sextet << 6) | (p - table);
            else bytes++;
        }
        // No check on outpos exceeding outlen!
        out[outpos++] = (sextet >> 16) & 0xFF;
        if (bytes < 2) out[outpos++] = (sextet >> 8) & 0xFF;
        if (bytes < 1) out[outpos++] = sextet & 0xFF;
    }
    return outpos;
}

int main() {
    char smallbuf[8];
    char *malicious = "AAAA"; // padded, decodes to 3 bytes, but we'll feed a long string
    // Attacker sends very long Base64 string, overflows smallbuf
    base64_decode("QUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB", 60, smallbuf, 8);
    return 0;
}

CVE-2026-11105 – Stack Buffer Overflow in Base64 Decoder

Severity: Critical

Overview

A custom Base64 decoding function does not validate the size of the output buffer, leading to a classic stack buffer overflow. An attacker can craft an oversized input to overwrite the return address and gain code execution.

Vulnerability Details

  • Type: Stack Buffer Overflow
  • Impact: Remote code execution (if exposed over network).
  • Root Cause: The decoder writes decoded bytes sequentially without ensuring the output pointer stays within the allocated buffer.

Exploit Demonstration

  1. Compile the vulnerable decoder (disable protections):
    gcc -o base64_vuln base64_vuln.c -fno-stack-protector -z execstack
    
  2. Run the exploit script to trigger the overflow:
    python exploit_base64_overflow.py
    
Download Tool