Out-of-Bounds Read Vulnerability in marcobambini Gravity Product
CVE-2026-90716
Key Information:
- Vendor
Marcobambini
- Status
- Vendor
- CVE Published:
- 14 September 2026
Badges
What is CVE-2026-90716?
An out-of-bounds read vulnerability has been identified in the Number Parser component of the marcobambini Gravity software, particularly in the parse_number_expression function within the file src/compiler/gravity_parser.c. This flaw allows remote attackers to manipulate inputs in a way that leads to unauthorized memory access, potentially compromising system integrity. The vulnerability is publicly exploitable, and users are strongly advised to upgrade to version 0.9.8, which includes a patch to mitigate this risk.
Affected Version(s)
Gravity 0.9.0
Gravity 0.9.1
Gravity 0.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
