Denial of Service Vulnerability in Zserio Framework by ndsev
CVE-2026-33524
7.5HIGH
What is CVE-2026-33524?
A vulnerability in the Zserio framework allows an attacker to craft a payload as small as 4-5 bytes that can trigger excessive memory allocation, leading to a Denial of Service (DoS) condition. This flaw results in processes crashing due to out-of-memory (OOM) errors. The issue has been addressed in version 2.18.1, where appropriate measures have been put into place to mitigate the risks associated with this vulnerability.
Affected Version(s)
zserio < 2.18.1
