CVE-2024-32655Active Exploitation

MEDIUMCVSS 8.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of parameter lengths. Both variables overflow when the sum of parameter lengths becomes too large. This causes Npgsql to write a message size that is too small when constructing a Postgres protocol message to send it over the network to the database. When parsing the message, the database will only read a small number of bytes and treat any following bytes as new messages while they belong to the old message. Attackers can abuse this to inject arbitrary Postgres protocol messages into the connection, leading to the execution of arbitrary SQL statements on the application's behalf. This vulnerability is fixed in 4.0.14, 4.1.13, 5.0.18, 6.0.11, 7.0.7, and 8.0.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-190

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-23: 1Active Exploitation · 2026-04-23: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-23: 104-23
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • CiberBaur@BotBauR
    Active Exploitation

    🚨 Acaba de confirmarse: Si usas Breeze Cache en WordPress, léelo ahora: **Hackers explotan vulnerabilidad crítica en Breeze Cache para subir archivos maliciosos** Los atacantes están aprovechando **CVE-2024-32655**, una falla sin autenticación en el plugin Breeze Cache (versión <2.0.8), para subir shells PHP y ejecutar código en servidores. No requiere credenciales. **Impacto:** - Más de 1 millón de instalaciones activas afectadas. - Compromiso total del servidor web si no se parchea. **Estado actual:** La versión 2.0.8+ ya está disponible. **Actualiza YA** y revisa logs de servidores. ¿Estás en riesgo? Revisa si usas Breeze Cache <2.0.8 y aplica el parche. #CiberseguridadMX #ZeroDay #CVE #WordPress Análisis técnico completo para defensores en el boletín semanal → bio https://www.bleepingcomputer.com/news/security/hackers-exploit-file-upload-bug-in-breeze-cache-wordpress-plugin/

    Post summary

    CVE‑2024‑32655 is actively exploited via an unauthenticated file‑upload flaw in Breeze Cache, affecting over one million WordPress sites; the 2.0.8 patch is available and must be applied immediately.

    0102068
    152 followersView on X

Explore more