THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9rm7-3qhh-h2mc (high) — Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)

[GHSA] GHSA-9rm7-3qhh-h2mc (high) — Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)

highgithub_advisoriesPublished 2026-09-17

GHSA-9rm7-3qhh-h2mc Severity: high CVE: CVE-2026-63126

Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)

Wire's protobuf decoders did not consistently validate attacker-controlled length-delimited sizes against the current reader bounds before computing cursor, limit, or pointer positions.

In the Kotlin runtime, `

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9rm7-3qhh-h2mc