CVE-2026-33524Disclosure(nds-association / zserio)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nds-association zserio systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can force memory allocations of up to 16 GB, crashing any process with an OOM error (Denial of Service). This vulnerability is fixed in 2.18.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zserio

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-04-24); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
zserio

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-24: 3Mentions · 2026-04-25: 1Mentions · 2026-04-28: 1Mentions · 2026-04-29: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-24: 3Technical Details · 2026-04-25: 1Technical Details · 2026-04-28: 104-2404-2504-2804-29
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-243
Disclosure3
2026-04-251
General1
2026-04-281
Disclosure1
2026-04-291
Patch1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33524 Denial of Service via Memory Exhaustion in Zserio Framework Before 2.18.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33524

    Post summary

    The text lists CVE‑2026‑33524 as a Denial of Service vulnerability due to memory exhaustion in Zserio Framework versions prior to 2.18.1, without providing exploitation evidence, PoC, or patch details.

    0100052
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 go-zserio, Unbounded Memory Allocation, #CVE-2026-33524 (Critical) https://dailycve.com/go-zserio-unbounded-memory-allocation-cve-2026-33524-critical/

    Post summary

    The text announces a new critical CVE-2026-33524 for go‑zserio related to an unbounded memory allocation, but provides no further exploitation or mitigation details.

    0001050
    183 followersView on X
  • Ryuji Yasukochi@m2labo@ryuji_yasu
    Patch

    NDS の中核シリアライザ zserio に脆弱性 2 件を報告し、CVE-2026-33524 / CVE-2026-33666 として公開されました(修正済)。NDS はトヨタ・BMW・ベンツなど世界 43 社の OEM が採用しています。 https://yasu-home.com/cve-2026-33524-zserio-vulnerability-explainer/

    Post summary

    Two CVEs (CVE-2026-33524 and CVE-2026-33666) affecting NDS's zserio serializer have been reported and patched; NDS is adopted by 43 OEMs worldwide.

    0000079
    263 followersView on X
  • cvereports@_cvereports
    Disclosure

    GHSA-XHJ4-G6W8-2XJW: CVE-2026-33524: Unbounded Memory Allocation in go-zserio The `go-zserio` library suffers from an Unbounded Memory Allocation vulnerability (CWE-770) during the deserialization of structured data. An unauthenticated remote attacker... https://cvereports.com/reports/GHSA-XHJ4-G6W8-2XJW

    Post summary

    The report discloses an Unbounded Memory Allocation (CWE‑770) vulnerability in go‑zserio affecting deserialization, but it provides no PoC, exploit tool, active exploitation evidence, patch, or debunking claim.

    0000019
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33524 Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can… https://www.cve.org/CVERecord?id=CVE-2026-33524

    Post summary

    CVE-2026-33524 is a vulnerability in the Zserio framework that allows an attacker to craft a very small payload (4‑5 bytes) to exploit the system prior to version 2.18.1.

    0000090
    57.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Multiple Platforms (C++/#Java/#Python/Go), Unbounded Memory Allocation, #CVE-2026-33524 (Critical) https://dailycve.com/multiple-platforms-c-java-python-go-unbounded-memory-allocation-cve-2026-33524-critical/

    Post summary

    The post announces CVE-2026-33524, a critical unbounded memory allocation vulnerability affecting multiple programming languages.

    0000033
    183 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnds-associationzserio---

Explore more