PT-2026-95098 · Wire · Wire
CVE-2026-61695
·
Published
2026-09-17
·
Updated
2026-09-29
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Wire versions prior to 6.4.1
Wire versions prior to 7.0.0-alpha04
Description
Wire's Swift runtime fails to reject negative lengths for
LENGTH DELIMITED fields when skipping an unknown START GROUP field. A crafted protobuf payload can cause the ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) function to pass a negative value to ReadBuffer.readData(count:). Because the buffer only checks the upper bound, the negative count reaches the Foundation Data(bytes:count:) initializer, triggering an unrecoverable process trap (SIGTRAP) and resulting in a denial of service. This issue occurs during the execution of ProtoDecoder.decode( :from:) and can be exploited without authentication, user interaction, or knowledge of the target schema.Recommendations
Upgrade to Wire version 6.4.1 or later.
Upgrade to Wire version 7.0.0-alpha04 or later.
Exploit
Fix
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wire