CVE-2026-33666General(nds-association / zserio)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nds-association zserio systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readBytes() / readString(), the setBitPosition() bounds check receives the overflowed value and is completely bypassed. The code then reads len bytes (512 MB) from a buffer that is only a few bytes long, causing a segmentation fault. This vulnerability is fixed in 2.18.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zserio

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
zserio

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-04-29: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-25: 104-2404-2504-29
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-241
General1
2026-04-251
Disclosure1
2026-04-291
Patch1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33666 Buffer Overflow in Zserio BitStreamReader Prior to Version 2.18.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33666

    Post summary

    The entry discloses a Buffer Overflow vulnerability (CVE‑2026‑33666) in Zserio BitStreamReader versions before 2.18.1, providing only technical details without PoC or exploitation evidence.

    0100089
    4.0K followersView on X
  • Ryuji Yasukochi@m2labo@ryuji_yasu
    Patch

    NDS の中核シリアライザ zserio に脆弱性 2 件を報告し、CVE-2026-33524 / CVE-2026-33666 として公開されました(修正済)。NDS はトヨタ・BMW・ベンツなど世界 43 社の OEM が採用しています。 https://yasu-home.com/cve-2026-33524-zserio-vulnerability-explainer/

    Post summary

    The NDS zserio serializer has two vulnerabilities (CVE-2026-33524 / CVE-2026-33666) that have been fixed, with an explanatory link provided.

    0000079
    263 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33666 Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readBytes() / readStri… https://www.cve.org/CVERecord?id=CVE-2026-33666

    Post summary

    The post merely references CVE‑2026‑33666 and links to the CVE record, without providing additional details or indicators of exploitation or mitigation.

    00000102
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnds-associationzserio---

Explore more