CWE-789
AllowedMemory Allocation with Excessive Size Value
Abstraction: Variant · Status: Draft
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
472 vulnerabilities reference this CWE, most recent first.
CVE-2026-103603 (GCVE-0-2026-103603)
Vulnerability from cvelistv5 – Published: 2026-10-02 07:10 – Updated: 2026-10-02 07:10- CWE-789 - Memory Allocation with Excessive Size Value
| URL | Tags |
|---|---|
| https://github.com/bcgit/bc-csharp/wiki/CVE-2026-103603 | vendor-advisory |
| https://github.com/bcgit/bc-csharp/commit/f47ad47… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | bc-csharp |
Affected:
0 , < 2.7.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"collectionURL": "https://www.nuget.org/packages/BouncyCastle.Cryptography",
"defaultStatus": "unaffected",
"packageName": "BouncyCastle.Cryptography",
"product": "bc-csharp",
"programFiles": [
"crypto/src/pqc/crypto/lms/HSSPublicKeyParameters.cs",
"crypto/src/pqc/crypto/lms/HSSSignature.cs"
],
"repo": "https://github.com/bcgit/bc-csharp",
"vendor": "Legion of the Bouncy Castle Inc.",
"versions": [
{
"lessThan": "2.7.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Discovered by Claude, Anthropic\u0027s AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory exhaustion via a public key encoding with an excessive level count, because the level count L read when parsing an HSS public key was not checked against the RFC 8554 maximum of 8, and signature parsing then allocated an array of L - 1 entries before reading any further signature data. A single verification can commit up to about 17 GB of memory or fail with an OutOfMemoryException."
}
],
"value": "Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory exhaustion via a public key encoding with an excessive level count, because the level count L read when parsing an HSS public key was not checked against the RFC 8554 maximum of 8, and signature parsing then allocated an array of L - 1 entries before reading any further signature data. A single verification can commit up to about 17 GB of memory or fail with an OutOfMemoryException."
}
],
"impacts": [
{
"descriptions": [
{
"lang": "en",
"value": "Denial of Service (memory exhaustion during HSS signature verification)"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T07:10:34.017Z",
"orgId": "91579145-5d7b-4cc5-b925-a0262ff19630",
"shortName": "bcorg"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/bcgit/bc-csharp/wiki/CVE-2026-103603"
},
{
"tags": [
"patch"
],
"url": "https://github.com/bcgit/bc-csharp/commit/f47ad47c7b5745b53d3f9ac711a5a419a272a5d7"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Unbounded HSS public key level count allows huge array allocation during signature verification",
"x_antReportIds": [
"ANT-2026-F7RBDSF7"
],
"x_generator": {
"engine": "Claude Opus 5.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "91579145-5d7b-4cc5-b925-a0262ff19630",
"assignerShortName": "bcorg",
"cveId": "CVE-2026-103603",
"datePublished": "2026-10-02T07:10:34.017Z",
"dateReserved": "2026-09-30T23:01:10.053Z",
"dateUpdated": "2026-10-02T07:10:34.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102820 (GCVE-0-2026-102820)
Vulnerability from cvelistv5 – Published: 2026-09-29 18:18 – Updated: 2026-09-30 20:11| URL | Tags |
|---|---|
| https://github.com/Eugeny/russh/security/advisori… | x_refsource_CONFIRM |
| https://github.com/Eugeny/russh/commit/5d566989eb… | x_refsource_MISC |
| https://github.com/Eugeny/russh/releases/tag/v0.63.2 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102820",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T20:11:00.619637Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T20:11:08.453Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "russh",
"vendor": "Eugeny",
"versions": [
{
"status": "affected",
"version": "\u003c 0.63.2"
}
]
},
{
"product": "pageant",
"vendor": "rust",
"versions": [
{
"status": "affected",
"version": "\u003c 0.2.3"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate\u0027s pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connect_pageant. A local process that impersonates the Pageant window can make query_pageant_direct allocate up to approximately 4 GiB and copy beyond the mapped view, reliably crashing a russh client and conditionally exposing adjacent committed memory. This issue is fixed in pageant 0.2.3."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-125",
"description": "CWE-125: Out-of-bounds Read",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789: Memory Allocation with Excessive Size Value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T18:18:43.297Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm"
},
{
"name": "https://github.com/Eugeny/russh/commit/5d566989ebabfdebfe6b33243d31765a0812260b",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Eugeny/russh/commit/5d566989ebabfdebfe6b33243d31765a0812260b"
},
{
"name": "https://github.com/Eugeny/russh/releases/tag/v0.63.2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Eugeny/russh/releases/tag/v0.63.2"
}
],
"source": {
"advisory": "GHSA-g4mp-vgx3-xrvm",
"discovery": "UNKNOWN"
},
"title": "pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-102820",
"datePublished": "2026-09-29T18:18:43.297Z",
"dateReserved": "2026-09-29T17:25:25.264Z",
"dateUpdated": "2026-09-30T20:11:08.453Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102809 (GCVE-0-2026-102809)
Vulnerability from cvelistv5 – Published: 2026-09-29 17:22 – Updated: 2026-09-29 18:14- CWE-789 - Memory Allocation with Excessive Size Value
| URL | Tags |
|---|---|
| https://github.com/PX4/PX4-Autopilot/pull/28586 | issue-trackingpatch |
| https://github.com/PX4/PX4-Autopilot/commit/46a77… | patch |
| https://github.com/PX4/PX4-Autopilot/blob/d6f12ad… | technical-description |
| https://github.com/PX4/PX4-Autopilot | product |
| https://www.vulncheck.com/advisories/px4-autopilo… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| PX4 | PX4-Autopilot |
Affected:
0 , ≤ 1.17.0
(semver)
cpe:2.3:a:px4:autopilot:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102809",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T18:13:24.208499Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T18:14:28.445Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/PX4/PX4-Autopilot/pull/28586"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "PX4-Autopilot",
"vendor": "PX4",
"versions": [
{
"lessThanOrEqual": "1.17.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:px4:autopilot:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.17.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Tianbo Wang"
},
{
"lang": "en",
"type": "finder",
"value": "Xiaoyang Chen"
}
],
"datePublic": "2026-09-28T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "Memory Allocation with Excessive Size Value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T17:22:41.803Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #28586",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/PX4/PX4-Autopilot/pull/28586"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/PX4/PX4-Autopilot/commit/46a77d8ad15e7929ef261c41083dffd1bbfa9f85"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/tests/test_file2.c#L86-L130"
},
{
"tags": [
"product"
],
"url": "https://github.com/PX4/PX4-Autopilot"
},
{
"name": "VulnCheck Advisory: PX4 Autopilot through 1.17.0 Stack Exhaustion via tests file2 Command",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-stack-exhaustion-via-tests-file2-command"
}
],
"title": "PX4 Autopilot through 1.17.0 Stack Exhaustion via tests file2 Command",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-102809",
"datePublished": "2026-09-29T17:22:41.803Z",
"dateReserved": "2026-09-29T17:11:36.089Z",
"dateUpdated": "2026-09-29T18:14:28.445Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102510 (GCVE-0-2026-102510)
Vulnerability from cvelistv5 – Published: 2026-09-30 08:01 – Updated: 2026-09-30 14:40- CWE-789 - Memory Allocation with Excessive Size Value. This covers the array pre-allocation (f017) and the transport read buffers (f018)
- CWE-190 - Integer Overflow or Wraparound. This covers the uint16 length and position wraps (f009) and the EIP packet size wrapping to 0 (f014)
- CWE-129 - Improper Validation of Array Index. This covers the ADS and KNXnet/IP index panics (f013, f015)
- CWE-674 - Uncontrolled Recursion. This covers the Go part of f045
| URL | Tags |
|---|---|
| https://lists.apache.org/thread.html/lw66k49p1jf7… | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.11.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102510",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:40:24.270117Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:40:31.604Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://golang.org/pkg",
"defaultStatus": "unaffected",
"packageName": "github.com/apache/plc4x/plc4go",
"packageURL": "pkg:golang/github.com/apache/plc4x/plc4go",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.11.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eInteger Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\u003cbr\u003ecausing a denial of service.\u003cbr\u003e\u003cbr\u003eThe individual defects are:\u003cbr\u003e- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\u003cbr\u003e- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\u003cbr\u003e- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\u003cbr\u003e- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\u003cbr\u003e- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by \u003ca href=\"https://cveprocess.apache.org/cve5/CVE-2026-102509\"\u003eCVE-2026-102509\u003c/a\u003e.\u003cbr\u003e\u003cbr\u003eAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \u003cbr\u003eadditional, independent protocol messages.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\ncausing a denial of service.\n\nThe individual defects are:\n- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\n- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\n- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\n- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .\n\nAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \nadditional, independent protocol messages.\n\nThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value. This covers the array pre-allocation (f017) and the transport read buffers (f018)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "CWE-190 Integer Overflow or Wraparound. This covers the uint16 length and position wraps (f009) and the EIP packet size wrapping to 0 (f014)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-129",
"description": "CWE-129 Improper Validation of Array Index. This covers the ADS and KNXnet/IP index panics (f013, f015)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled Recursion. This covers the Go part of f045",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:01:43.024Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/lw66k49p1jf7w0p7h6yg6jqvysborxrs"
}
],
"source": {
"discovery": "INTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-08-11T12:16:00.000Z",
"value": "found during the internal security review"
},
{
"lang": "en",
"time": "2026-09-07T12:17:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102510",
"datePublished": "2026-09-30T08:01:43.024Z",
"dateReserved": "2026-09-29T11:41:34.033Z",
"dateUpdated": "2026-09-30T14:40:31.604Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102509 (GCVE-0-2026-102509)
Vulnerability from cvelistv5 – Published: 2026-09-30 08:00 – Updated: 2026-09-30 14:40- CWE-789 - Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024).
- CWE-770 - Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3).
- CWE-674 - Uncontrolled Recursion. This covers the nested mspec types (f045).
| URL | Tags |
|---|---|
| https://lists.apache.org/thread.html/qngc85qhnlj7… | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.10.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102509",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:39:55.913450Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:40:06.881Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-spi",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-spi",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-opcua",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-opcua",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Abhinav Agarwal"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eMemory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\u003cbr\u003e\u003cbr\u003eIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server\u0027s identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \u003cbr\u003eimpersonate it.\u003cbr\u003e\u003cbr\u003eThe individual defects are:\u003cbr\u003e- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\u003cbr\u003e- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\u003cbr\u003e- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\u003cbr\u003e- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\u003cbr\u003e- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by \u003ca href=\"https://cveprocess.apache.org/cve5/CVE-2026-102510\"\u003eCVE-2026-102510\u003c/a\u003e.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\n\nIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server\u0027s identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \nimpersonate it.\n\nThe individual defects are:\n- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\n- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\n- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\n- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .\n\nThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024).",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "CWE-770 Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3).",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled Recursion. This covers the nested mspec types (f045).",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:00:27.709Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/qngc85qhnlj7kpk3z58z0xlxhz2tn6gp"
}
],
"source": {
"discovery": "EXTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-07-09T12:11:00.000Z",
"value": "reported to the Apache Security Team"
},
{
"lang": "en",
"time": "2026-07-10T12:11:00.000Z",
"value": "reported issues fixed on develop (a2dbb6bfc0, 5a4d5bdb4c)"
},
{
"lang": "en",
"time": "2026-09-07T12:12:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102509",
"datePublished": "2026-09-30T08:00:27.709Z",
"dateReserved": "2026-09-29T11:41:21.875Z",
"dateUpdated": "2026-09-30T14:40:06.881Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102504 (GCVE-0-2026-102504)
Vulnerability from cvelistv5 – Published: 2026-10-01 13:11 – Updated: 2026-10-01 19:31{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-10-01T15:08:20.353Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/10/01/9"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-102504",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:31:27.061525Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:31:30.976Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"modules": [
"Imager"
],
"packageName": "Imager",
"packageURL": "pkg:cpan/Imager",
"programFiles": [
"raw.c"
],
"programRoutines": [
{
"name": "i_readraw_wiol"
}
],
"repo": "https://github.com/tonycoz/imager",
"versions": [
{
"lessThan": "1.037",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ahanwate"
}
],
"descriptions": [
{
"lang": "en",
"value": "Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.\n\nNothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager\u0027s allocator calls exit(3).\n\nPassing an untrusted raw_datachannels value to Imager-\u003eread() triggers an uncatchable exit."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "CWE-190 Integer Overflow or Wraparound",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:11:38.558Z",
"orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"shortName": "CPANSec"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/tonycoz/imager/security/advisories/GHSA-g549-r73g-x7x6"
},
{
"tags": [
"patch"
],
"url": "https://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679.patch"
},
{
"tags": [
"release-notes"
],
"url": "https://metacpan.org/release/TONYC/Imager-1.037/changes"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to Imager 1.037 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Version 1.037 released with fix."
}
],
"title": "Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol",
"x_generator": {
"engine": "cpansec-cna-tool 0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"assignerShortName": "CPANSec",
"cveId": "CVE-2026-102504",
"datePublished": "2026-10-01T13:11:38.558Z",
"dateReserved": "2026-09-29T11:12:58.569Z",
"dateUpdated": "2026-10-01T19:31:30.976Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96260 (GCVE-0-2026-96260)
Vulnerability from cvelistv5 – Published: 2026-09-22 20:34 – Updated: 2026-09-23 15:06- CWE-789 - Memory Allocation with Excessive Size Value
| URL | Tags |
|---|---|
| https://mattermost.com/security-updates | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Mattermost | Mattermost |
Affected:
11.9.0 , ≤ 11.9.1
(semver)
Affected: 11.8.0 , ≤ 11.8.5 (semver) Affected: 11.7.0 , ≤ 11.7.10 (semver) Affected: 11.10.0 , ≤ 11.10.1 (semver) Unaffected: 11.11.0 Unaffected: 11.9.2 Unaffected: 11.8.6 Unaffected: 11.7.11 Unaffected: 11.10.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96260",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T15:05:56.037132Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T15:06:07.254Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Mattermost",
"vendor": "Mattermost",
"versions": [
{
"lessThanOrEqual": "11.9.1",
"status": "affected",
"version": "11.9.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "11.8.5",
"status": "affected",
"version": "11.8.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "11.7.10",
"status": "affected",
"version": "11.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "11.10.1",
"status": "affected",
"version": "11.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "11.11.0"
},
{
"status": "unaffected",
"version": "11.9.2"
},
{
"status": "unaffected",
"version": "11.8.6"
},
{
"status": "unaffected",
"version": "11.7.11"
},
{
"status": "unaffected",
"version": "11.10.2"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "alimursaliyev"
}
],
"descriptions": [
{
"lang": "en",
"value": "Mattermost versions 11.9.x \u003c= 11.9.1, 11.8.x \u003c= 11.8.5, 11.7.x \u003c= 11.7.10, 11.10.x \u003c= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a denial of service via a large request body sent to a plugin endpoint.. Mattermost Advisory ID: MMSA-2026-00775"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789: Memory Allocation with Excessive Size Value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T20:34:49.141Z",
"orgId": "9302f53e-dde5-4bf3-b2f2-a83f91ac0eee",
"shortName": "Mattermost"
},
"references": [
{
"name": "MMSA-2026-00775",
"tags": [
"vendor-advisory"
],
"url": "https://mattermost.com/security-updates"
}
],
"solutions": [
{
"lang": "en",
"value": "Update Mattermost to versions 11.11.0, 11.9.2, 11.8.6, 11.7.11, 11.10.2 or higher."
}
],
"source": {
"advisory": "MMSA-2026-00775",
"defect": [
"https://mattermost.atlassian.net/browse/MM-70503"
],
"discovery": "EXTERNAL"
},
"title": "Mattermost server missing request body size limit on plugin routes allows denial of service by an authenticated user",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "9302f53e-dde5-4bf3-b2f2-a83f91ac0eee",
"assignerShortName": "Mattermost",
"cveId": "CVE-2026-96260",
"datePublished": "2026-09-22T20:34:49.141Z",
"dateReserved": "2026-09-22T20:00:26.276Z",
"dateUpdated": "2026-09-23T15:06:07.254Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94626 (GCVE-0-2026-94626)
Vulnerability from cvelistv5 – Published: 2026-09-21 22:04 – Updated: 2026-09-24 22:54- CWE-789 - Memory Allocation with Excessive Size Value
| URL | Tags |
|---|---|
| https://github.com/vllm-project/vllm/pull/51137 | issue-trackingpatch |
| https://github.com/vllm-project/vllm/blob/v0.29.0… | technical-description |
| https://github.com/vllm-project/vllm/blob/v0.29.0… | technical-description |
| https://github.com/vllm-project/vllm | product |
| https://www.vulncheck.com/advisories/vllm-through… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| vllm-project | vllm |
Affected:
0 , ≤ 0.29.0
(semver)
cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94626",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T22:54:32.814414Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T22:54:41.241Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:pypi/vllm",
"product": "vllm",
"vendor": "vllm-project",
"versions": [
{
"lessThanOrEqual": "0.29.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*",
"versionEndIncluding": "0.29.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Mingkai Yu"
},
{
"lang": "en",
"type": "finder",
"value": "Jiapeng Li"
},
{
"lang": "en",
"type": "finder",
"value": "Jiajia Liu"
}
],
"datePublic": "2026-08-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "Memory Allocation with Excessive Size Value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T22:04:15.352Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #51137",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/vllm-project/vllm/pull/51137"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/utils.py#L569-L573"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/v1/nixl/metadata.py#L277"
},
{
"tags": [
"product"
],
"url": "https://github.com/vllm-project/vllm"
},
{
"name": "VulnCheck Advisory: vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/vllm-through-0.29.0-memory-exhaustion-via-unvalidated-nixl-tp-size"
}
],
"title": "vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-94626",
"datePublished": "2026-09-21T22:04:15.352Z",
"dateReserved": "2026-09-21T21:42:28.781Z",
"dateUpdated": "2026-09-24T22:54:41.241Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93307 (GCVE-0-2026-93307)
Vulnerability from cvelistv5 – Published: 2026-09-17 21:45 – Updated: 2026-09-23 17:53| URL | Tags |
|---|---|
| https://vuldb.com/vuln/406593 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/406593/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-93307 | third-party-advisory |
| https://vuldb.com/submit/942297 | third-party-advisory |
| https://vuldb.com/submit/942306 | third-party-advisory |
| https://lf-o-ran-sc.atlassian.net/browse/SMO-201 | related |
| https://gist.github.com/fklement/1c1ff92588944a02… | exploit |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93307",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T17:53:43.455806Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T17:53:54.780Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://vuldb.com/submit/942297"
},
{
"tags": [
"exploit"
],
"url": "https://vuldb.com/submit/942306"
},
{
"tags": [
"exploit"
],
"url": "https://lf-o-ran-sc.atlassian.net/browse/SMO-201"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:o-ran-sc:smo_oam:*:*:*:*:*:*:*:*"
],
"modules": [
"VES Collector"
],
"product": "SMO OAM",
"vendor": "O-RAN-SC",
"versions": [
{
"status": "affected",
"version": "2025-06-10"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "fklement (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a bug report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "Uncontrolled Memory Allocation",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T21:45:10.125Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-406593 | O-RAN-SC SMO OAM VES Collector memory allocation",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/406593"
},
{
"name": "VDB-406593 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/406593/cti"
},
{
"name": "CVE-2026-93307 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-93307"
},
{
"name": "Submit #942297 | O-RAN-SC SMO/OAM L-Release CWE-789 Memory Allocation with Excessive Size Value",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/942297"
},
{
"name": "Submit #942306 | O-RAN-SC SMO/OAM L-Release CWE-789 Memory Allocation with Excessive Size Value (Duplicate)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/942306"
},
{
"tags": [
"related"
],
"url": "https://lf-o-ran-sc.atlassian.net/browse/SMO-201"
},
{
"tags": [
"exploit"
],
"url": "https://gist.github.com/fklement/1c1ff92588944a021ceb2b5e894973c5"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-17T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-17T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-17T19:11:01.000Z",
"value": "VulDB entry last update"
}
],
"title": "O-RAN-SC SMO OAM VES Collector memory allocation",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-93307",
"datePublished": "2026-09-17T21:45:10.125Z",
"dateReserved": "2026-09-17T17:05:34.780Z",
"dateUpdated": "2026-09-23T17:53:54.780Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93019 (GCVE-0-2026-93019)
Vulnerability from cvelistv5 – Published: 2026-09-18 13:58 – Updated: 2026-09-18 17:28{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-09-18T17:06:59.404Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/18/9"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-93019",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T17:28:31.210557Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:28:49.711Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/tonycoz/imager/security/advisories/GHSA-p4vw-rc54-p2c2"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"modules": [
"Imager"
],
"packageName": "Imager",
"packageURL": "pkg:cpan/Imager",
"programFiles": [
"tga.c"
],
"programRoutines": [
{
"name": "tga_palette_read"
}
],
"repo": "https://github.com/tonycoz/imager",
"versions": [
{
"lessThan": "1.036",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "router0mail"
}
],
"descriptions": [
{
"lang": "en",
"value": "Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read.\n\nThe reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager\u0027s allocator calls exit(3).\n\nReading an attacker-supplied file through Imager-\u003eread() triggers an uncatchable exit."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-196",
"description": "CWE-196 Unsigned to Signed Conversion Error",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T13:58:12.083Z",
"orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"shortName": "CPANSec"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/tonycoz/imager/security/advisories/GHSA-p4vw-rc54-p2c2"
},
{
"tags": [
"patch"
],
"url": "https://github.com/tonycoz/imager/commit/74ed50e0625f9f51054e595bb4a8da92c1e0d571.patch"
},
{
"tags": [
"release-notes"
],
"url": "https://metacpan.org/release/TONYC/Imager-1.036/changes"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to Imager 1.036 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"timeline": [
{
"lang": "en",
"time": "2026-09-18T00:00:00.000Z",
"value": "Version 1.036 released with fix."
}
],
"title": "Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read",
"x_generator": {
"engine": "cpansec-cna-tool 0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"assignerShortName": "CPANSec",
"cveId": "CVE-2026-93019",
"datePublished": "2026-09-18T13:58:12.083Z",
"dateReserved": "2026-09-17T14:56:50.796Z",
"dateUpdated": "2026-09-18T17:28:49.711Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
Perform adequate input validation against any value that influences the amount of memory that is allocated. Define an appropriate strategy for handling requests that exceed the limit, and consider supporting a configuration option so that the administrator can extend the amount of memory to be used if necessary.
Mitigation
Run your program using system-provided resource limits for memory. This might still cause the program to crash or exit, but the impact to the rest of the system will be minimized.
No CAPEC attack patterns related to this CWE.