CVE-2026-9500
Last modified
CVE-2026-9500 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-9500?
How severe is CVE-2026-9500?
How do I fix CVE-2026-9500?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9494An information disclosure vulnerability exists in Canonical …5.5
- CVE-2026-9495Versions of the package @koa/router from 14.0.0 and before 1…7.3
- CVE-2026-9496Versions of the package pacote from 11.2.7 and before 21.5.1…7.7
- CVE-2026-9497A flaw has been found in changmingxie tcc-transaction up to …6.3
- CVE-2026-9498A vulnerability has been found in Dromara lamp-cloud up to 5…6.3
- CVE-2026-9499An out-of-bounds read (buffer over-read) vulnerability exist…6.3
- CVE-2026-9501A vulnerability was determined in GNU LibreDWG up to 0.14. T…3.3
- CVE-2026-9502A vulnerability was identified in GNU LibreDWG up to 0.14. T…5.3
- CVE-2026-9503A security flaw has been discovered in GNU LibreDWG up to 0.…3.3
- CVE-2026-9504A weakness has been identified in GNU LibreDWG up to 0.14. A…3.3
- CVE-2026-9506This vulnerability exists in Bagisto due to improper validat…8.7
- CVE-2026-9507A session fixation vulnerability has been identified in osTi…5.1
Are you affected by CVE-2026-9500?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
