Nicotine+ · Nicotine+ · CVE-2026-68911
**Name of the Vulnerable Software and Affected Versions**
Nicotine+ versions prior to 3.3.11
**Description**
A modified remote client can send zlib-compressed peer messages containing a decompression bomb, which is a malicious archive designed to crash a system by consuming excessive resources during decompression. This process exhausts the available memory of the recipient's operating system.
**Recommendations**
Update to version 3.3.11.