CVE-2026-26209Medium· 5.5▾ SunlitA flaw was found in cbor2, a library for encoding and decoding Concise Binary Object Representation (CBOR) data. A remote attacker can exploit this vulnerability by sending a specially crafted CBOR payload containing deeply nested structur…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
Last analysed / modified upstream
7.5 → 5.5
high → medium
0.4% → 0.6%
A flaw was found in cbor2, a library for encoding and decoding Concise Binary Object Representation (CBOR) data. A remote attacker can exploit this vulnerability by sending a specially crafted CBOR payload containing deeply nested structures. This can cause the application to crash due to uncontrolled recursion, leading to a complete Denial of Service (DoS) for the affected application.
cbor2: cbor2: Denial of Service due to uncontrolled recursion via crafted CBOR payloads — rated Moderate by Red Hat. Released 2026-03-23, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
For more information visit https://access.redhat.com/errata/RHSA-2026:19724 https://access.redhat.com/errata/RHSA-2026:19724 For more information visit https://access.redhat.com/errata/RHSA-2026:19725 https://access.redhat.com/errata/RHSA-2026:19725 For more information visit https://access.redhat.com/errata/RHSA-2026:16030 https://access.redhat.com/errata/RHSA-2026:16030
Affected packages:
cbor2 < 5.9.0Patched in:
cbor2 5.9.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6855High· 7.1instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write (CVE-2026-6855)
CVE-2026-31221High· 8.0pytorch-lightning: PyTorch-Lightning: Arbitrary code execution via insecure deserialization of checkpoint files (CVE-2026-31221)
CVE-2025-69228Medium· 6.8aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request (CVE-2025-69228)
CVE-2025-62426Medium· 6.5vllm: vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` (CVE-2025-624…
CVE-2025-11374Medium· 6.5github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of service (CVE-2025-11374)
CVE-2026-18618High· 7.5A flaw was found in ml-metadata