Decompression Bomb Vulnerability in Nicotine+ by Nicotine+ Team
CVE-2026-68911
8.7HIGH
What is CVE-2026-68911?
The Nicotine+ client for the Soulseek peer-to-peer network is vulnerable to a decompression bomb attack that can exhaust system memory. Malicious remote clients may exploit this vulnerability by sending specially crafted zlib-compressed peer messages, leading to potential service disruption on affected systems. This issue has been fixed in Nicotine+ version 3.3.11, so users are strongly advised to update to the latest version to ensure continued security and performance.
Affected Version(s)
nicotine-plus < 3.3.11
