Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0204 | cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object. Version 5.6.2 contains a patch for this issue. |
Github GHSA |
GHSA-375g-39jq-vq7m | Potential buffer overflow in CBOR2 decoder |
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:agronholm:cbor2:5.5.1:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Thu, 02 Jan 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agronholm
Agronholm cbor2 Fedoraproject Fedoraproject fedora |
|
| CPEs | cpe:2.3:a:agronholm:cbor2:*:*:*:*:*:python:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
|
| Vendors & Products |
Agronholm
Agronholm cbor2 Fedoraproject Fedoraproject fedora |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:41:03.627Z
Reserved: 2024-02-14T17:40:03.687Z
Link: CVE-2024-26134
Updated: 2024-08-01T23:59:32.554Z
Status : Analyzed
Published: 2024-02-19T23:15:07.810
Modified: 2025-01-02T14:18:48.553
Link: CVE-2024-26134
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA