在 marcobambini 的 Gravity 软件(版本 0.9.7 及以下)中检测到一处安全漏洞。该漏洞影响 文件中 函数所在的“数字解析器”组件。当对输入进行特定操作时,会触发越界读取(out-of-bounds read)。攻击者可远程发起该攻击。利用该漏洞的利用代码(exploit)已公开,并可能已被使用。升级至版本 0.9.8 可修复此问题。对应的补丁提交名为 。建议升级受影响的组件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| marcobambini | Gravity | 0.9.0 |
cpe:2.3:a:marcobambini:gravity:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90715 | 7.3 HIGH | marcobambini Gravity udp json-parser gravity_json.c integer overflow |
| CVE-2026-90714 | 6.3 MEDIUM | marcobambini Gravity JSON parser gravity_json.c memory corruption |
No comments yet