PT-2026-93890 · Wire · Wire

CVE-2026-63126

·

Published

2026-08-25

·

Updated

2026-09-17

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wire versions prior to 6.4.5 Wire versions prior to 7.0.0-alpha04
Description An integer overflow exists in the protobuf and gRPC decoder. Protobuf readers fail to consistently validate attacker-controlled lengths against the logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin, the ProtoAdapter.decode(ByteArray) and ProtoAdapter.decode(ByteString) functions utilize ByteArrayProtoReader32.internalNextLengthDelimited(), where an oversized positive length can cause pos + length to wrap to a negative limit, bypassing negative-length checks. Other affected paths include ProtoReader, ReadBuffer.readVarint(), ReadBuffer.verifyAdditional(count:), packed-repeated, nested-message, and ProtoDecoder.decodeSizeDelimited( :from:). These paths may cross logical boundaries, perform pointer arithmetic, reserve capacity, or convert unrepresentable sizes before verifying the existence of the requested bytes. A remote attacker providing malformed protobuf bytes can trigger unchecked exceptions, traps, out-of-bounds behavior, or excessive allocation, leading to a denial of service.
Recommendations Update to version 6.4.5. Update to version 7.0.0-alpha04.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14835
CVE-2026-63126
GHSA-9RM7-3QHH-H2MC

Affected Products

Wire