{"id":"CVE-2026-107611","title":"An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending …","summary":"An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending …","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cwe":["CWE-125"],"vendor":"GlavSoft","product":"TightVNC","affected":["TightVNC < 2.8.88"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:10:00.133","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107611","references":[{"url":"https://sourceforge.net/p/vnc-tight/bugs/1657/","label":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://www.tightvnc.com/whatsnew.php","label":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-08T14:02:42.563819Z"},"ingestedAt":"2026-10-08T14:47:16.340Z","slug":"CVE-2026-107611","body":"## Overview\n\nAn out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}