CVE-2026-33524
Last modified
CVE-2026-33524 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can force memory allocations of up to 16 GB, crashing any process with an OOM error (Denial of Service). EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can force memory allocations of up to 16 GB, crashing any process with an OOM error (Denial of Service). This vulnerability is fixed in 2.18.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nds-Association | Zserio | < 2.18.1 |
References
- https://github.com/ndsev/zserio/security/advisories/GHSA-cwq5-8pvq-j65jExploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33524?
How severe is CVE-2026-33524?
How do I fix CVE-2026-33524?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33516xrdp is an open source RDP server. Versions through 0.10.5 c…9.1
- CVE-2026-33517Mantis Bug Tracker (MantisBT) is an open source issue tracke…6.1
- CVE-2026-33518An incorrect privilege assignment vulnerability exists in Es…7.2
- CVE-2026-33519An incorrect authorization vulnerability exists in Esri Port…9.8
- CVE-2026-3352The Easy PHP Settings plugin for WordPress is vulnerable to …7.2
- CVE-2026-33523HTTP response splitting vulnerability in multiple Apache HTT…6.5
- CVE-2026-33525Authelia is an open-source authentication and authorization …6.1
- CVE-2026-33526Squid is a caching proxy for the Web. Prior to version 7.5, …7.5
- CVE-2026-33527Parse Server is an open source backend that can be deployed …4.3
- CVE-2026-33528GoDoxy is a reverse proxy and container orchestrator for sel…6.5
- CVE-2026-33529Zoraxy is a general purpose HTTP reverse proxy and forwardin…8.8
- CVE-2026-3353The Comment SPAM Wiper plugin for WordPress is vulnerable to…4.4
Are you affected by CVE-2026-33524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
