CVE-2026-63209

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7.

Published
September 29, 2026 3:17 PM
Last Modified
September 29, 2026 3:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-190 CWE-787

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.