CVE-2026-33524
EUVD-2026-2559124.04.2026, 19:17
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can force memory allocations of up to 16 GB, crashing any process with an OOM error (Denial of Service). This vulnerability is fixed in 2.18.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nds-association | zserio | 𝑥 < 2.18.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration