THREAT OPS › Threat News › [GHSA] GHSA-9rm7-3qhh-h2mc (high) — Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
[GHSA] GHSA-9rm7-3qhh-h2mc (high) — Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
GHSA-9rm7-3qhh-h2mc Severity: high CVE: CVE-2026-63126
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
Wire's protobuf decoders did not consistently validate attacker-controlled length-delimited sizes against the current reader bounds before computing cursor, limit, or pointer positions.
In the Kotlin runtime, `
Indicators of compromise
- 25ebcabb9ab7f12d1d77af75ecbc51726fddc015sha1
- CVE-2026-45799cve
- CVE-2026-63126cve
- CVE-2026-61695cve
Original source: https://github.com/advisories/GHSA-9rm7-3qhh-h2mc