PT-2026-93890 · Wire · Wire
CVE-2026-63126
·
Published
2026-08-25
·
Updated
2026-09-17
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Wire versions prior to 6.4.5
Wire versions prior to 7.0.0-alpha04
Description
An integer overflow exists in the protobuf and gRPC decoder. Protobuf readers fail to consistently validate attacker-controlled lengths against the logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin, the
ProtoAdapter.decode(ByteArray) and ProtoAdapter.decode(ByteString) functions utilize ByteArrayProtoReader32.internalNextLengthDelimited(), where an oversized positive length can cause pos + length to wrap to a negative limit, bypassing negative-length checks. Other affected paths include ProtoReader, ReadBuffer.readVarint(), ReadBuffer.verifyAdditional(count:), packed-repeated, nested-message, and ProtoDecoder.decodeSizeDelimited( :from:). These paths may cross logical boundaries, perform pointer arithmetic, reserve capacity, or convert unrepresentable sizes before verifying the existence of the requested bytes. A remote attacker providing malformed protobuf bytes can trigger unchecked exceptions, traps, out-of-bounds behavior, or excessive allocation, leading to a denial of service.Recommendations
Update to version 6.4.5.
Update to version 7.0.0-alpha04.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wire