CVE-2024-26134

HIGH

Agronholm Cbor2 < 5.6.2 - Buffer Overflow

Title source: rule
STIX 2.1

Description

cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object. Version 5.6.2 contains a patch for this issue.

Scores

CVSS v3 7.5
EPSS 0.0109
EPSS Percentile 78.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (5)
agronholm/cbor2 5.5.1 - 5.6.2
fedoraproject/fedora 38
fedoraproject/fedora 39
fedoraproject/fedora 40
pypi/cbor2 5.5.1 - 5.6.2PyPI
Published Feb 19, 2024
Tracked Since Feb 18, 2026