CVE-2026-20777Disclosure(libbiosig_project / libbiosig)

LOWCVSS 8.1 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libbiosig

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Products
libbiosig

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-03: 4Technical Details · 2026-03-03: 403-03
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20777 Heap-Based Buffer Overflow in Biosig Project libbiosig Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20777

    Post summary

    The post announces a heap-based buffer overflow in the Biosig Project's libbiosig library that allows remote code execution, linking to a vulnerability detail page.

    0000045
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-20777 - High A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file ca... https://www.thehackerwire.com/vulnerability/CVE-2026-20777/ https://t.co/lTMf9wFSou

    Post summary

    The post announces a heap‑based buffer overflow in libbiosig 3.9.2, detailing the affected component but providing no PoC, exploit, or patch information.

    0000041
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20777 A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A speci… https://www.cve.org/CVERecord?id=CVE-2026-20777 ----- Traducción: CVE-2026-20777 Exi… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑20777, a heap‑based buffer overflow in libbiosig, without providing PoC, exploit, or patch details.

    0000028
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20777 A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A speci… https://www.cve.org/CVERecord?id=CVE-2026-20777

    Post summary

    The text announces a heap-based buffer overflow vulnerability in libbiosig 3.9.2, without providing PoC, exploit, or patch details.

    00000169
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibbiosig_projectlibbiosig3.9.2--

Explore more