CVE-2026-33524
HIGHZserio: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization
Title source: cnaDescription
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can force memory allocations of up to 16 GB, crashing any process with an OOM error (Denial of Service). This vulnerability is fixed in 2.18.1.
Scores
CVSS v3
7.5
EPSS
0.0006
EPSS Percentile
17.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-789
Status
published
Products (2)
nds-association/zserio
< 2.18.1
ndsev/zserio
< 2.18.1
Published
Apr 24, 2026
Tracked Since
Apr 24, 2026