在 marcobambini 的 Gravity 0.9.7 及更早版本中发现了一个安全漏洞。受影响的组件是 JSON 解析器中 文件里的某个未知函数。该缺陷会导致内存破坏(memory corruption)。攻击者可以从远程触发此漏洞,且利用该漏洞的攻击方法(exploit)已公开,可能被用于发起攻击。 解决方案: 升级到 0.9.8 版本即可解决该问题。相关补丁的提交哈希为 。建议将受影响的组件升级至最新版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| marcobambini | Gravity | 0.9.0 |
cpe:2.3:a:marcobambini:gravity:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90715 | 7.3 HIGH | marcobambini Gravity udp json-parser gravity_json.c integer overflow |
| CVE-2026-90716 | 5.5 MEDIUM | marcobambini Gravity Number gravity_parser.c parse_number_expression out-of-bounds |
No comments yet