PT-2026-95098 · Wire · Wire

CVE-2026-61695

·

Published

2026-09-17

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wire versions prior to 6.4.1 Wire versions prior to 7.0.0-alpha04
Description Wire's Swift runtime fails to reject negative lengths for LENGTH DELIMITED fields when skipping an unknown START GROUP field. A crafted protobuf payload can cause the ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) function to pass a negative value to ReadBuffer.readData(count:). Because the buffer only checks the upper bound, the negative count reaches the Foundation Data(bytes:count:) initializer, triggering an unrecoverable process trap (SIGTRAP) and resulting in a denial of service. This issue occurs during the execution of ProtoDecoder.decode( :from:) and can be exploited without authentication, user interaction, or knowledge of the target schema.
Recommendations Upgrade to Wire version 6.4.1 or later. Upgrade to Wire version 7.0.0-alpha04 or later.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61695
GHSA-86WM-R4C5-2RC9

Affected Products

Wire