Severity: HighAction: Mitigate
lwIP (Lightweight IP)
Mitigate
No complete fix is indicated yet.
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.
lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Developments from the last 30 days, newest first.
CVE-2026-91018 scored CVSS 8.7
Basis: NIST National Vulnerability Database
lwIP (Lightweight IP)
Basis: CISA Cybersecurity Advisories (government advisory)
No complete fix is indicated yet.