# CVE-2026-8023 — zephyrproject zephyr

> As of 2026-06-30, CVE-2026-8023 is a HIGH-severity vulnerability in zephyrproject zephyr, CVSS v3.1 7.5, EPSS 0.6% (48.1th percentile). No Threadlinqs-tracked threat campaign has been attributed to CVE-2026-8023 as of 2026-06-30; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

**Last updated:** 2026-06-30

## What is CVE-2026-8023?

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both the HTTP/1 and HTTP/2 front-ends placed the raw, attacker-controlled request path into client-url_buffer (assembled in on_url() for HTTP/1 and copied verbatim from the :path pseudo-header for HTTP/2) without resolving ./.. segments. The static-FS handler then built the on-disk filename by directly concatenating the configured root with that raw URL (snprintk(fname, ..., "%s%s", static_fs_detail-fs_path, client-url_buffer) at http_server_http1.c:603 and http_server_http2.c:490) and opened it with fs_open(fname, FS_O_READ). Because the handler is reached via wildcard/leading-dir (fnmatch FNM_LEADING_DIR) or fallback resource matching, a request such as GET /<prefix/../../<file is dispatched to the handler and, after the underlying filesystem (e.g. LittleFS/FAT) resolves the .. segments, escapes the configured web root, letting an unauthenticated remote client read arbitrary readable files on the mounted volume (information disclosure). The HTTP server requires no TLS or authentication to reach this path. The fix adds http_server_remove_dot_segments(), which canonicalizes the path portion of the URL before resource lookup in both protocol handlers, neutralizing the traversal. Affects releases v4.0.0 through v4.4.0 for deployments that register a static-filesystem resource.

The record classifies CVE-2026-8023 under weakness classes [CWE-22](https://intel.threadlinqs.com/cwe/CWE-22), [CWE-23](https://intel.threadlinqs.com/cwe/CWE-23). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction, and has high impact on confidentiality. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 98 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 7.5 — HIGH (`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N`)
- **EPSS (FIRST):** 0.6% probability of exploitation in the next 30 days, higher than 48.1% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 7.7/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2026-06-29, last modified 2026-06-30

## Is CVE-2026-8023 being exploited?

Weaponised exploit code for CVE-2026-8023 is publicly available. 1 public proof-of-concept repository is tracked for this identifier. It currently carries a trending score of 50 in the Threadlinqs vulnerability feed.

- [ret2c/CVE-2026-8023](https://github.com/ret2c/CVE-2026-8023) (github)

## Affected products and versions

- [zephyrproject](https://intel.threadlinqs.com/vendors/zephyrproject): zephyr

## How to fix CVE-2026-8023

No vendor patch reference has been recorded for CVE-2026-8023 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

## Threat activity tracking CVE-2026-8023

No threat campaign in the Threadlinqs corpus currently references CVE-2026-8023, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, public proof-of-concept repositories. Last verified by Threadlinqs on 2026-07-01. This product uses the NVD API but is not endorsed or certified by the NVD.

**Vendor advisory and patch**

- [github.com — patch](https://github.com/zephyrproject-rtos/zephyr/commit/f4a423c98554f209c5d2f22f041822422c9263b8)

**Other references**

- [github.com](https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hch3-53g6-jj3h)

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-8023
Full detection coverage and IOCs for threats exploiting CVE-2026-8023 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
