VDB

CVE-2024-26134

CVE-2024-26134 PUBLISHED CVSS 7.5 HIGH

cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object. Version 5.6.2 contains a patch for this issue.

EPSS 1.18% · 65.5th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
1.18%
65.5th percentile

Affected Products

VendorProductVersions
fedoraprojectfedora40, 38, 40
agronholmcbor25.5.1, 5.5.1
agronholmcbor25.5.1, >= 5.5.1, < 5.6.2, *
PyPIcbor25.5.1, 5.5.1

Timeline

  • Jan 21, 1970 Security Advisory
  • Feb 19, 2024 PoC Published
  • Feb 19, 2024 CVE Published
  • Feb 20, 2024 EPSS Score
  • Feb 20, 2024 PoC Published
  • Feb 20, 2024 PoC Published
  • Mar 18, 2024 EPSS Score
  • Apr 14, 2024 EPSS Score
  • Jun 7, 2024 EPSS Score
  • Jul 4, 2024 EPSS Score
  • Jul 31, 2024 EPSS Score
  • Aug 27, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›