CVE-2026-40504Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string literals at global scope. Attackers can exploit insufficient bounds checking in gravity_fiber_reassign() to corrupt heap metadata and achieve arbitrary code execution in applications that evaluate untrusted scripts.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-04-16); latest day: 2
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-04-16: 5Mentions · 2026-05-12: 2PoC Mentioned / Linked · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 5Technical Details · 2026-05-12: 104-1605-12
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-165
Disclosure4Patch1
2026-05-122
General2
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-40504 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post cites a critical advisory for CVE-2026-40504 with CVSS details, but offers none of the typical exploit or mitigation information.

    1000030
    210 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Heap Buffer Overflow in #Creolabs #Gravity. CVE-2026-40504 CVSS: 9.8. Remote attackers can exploit it without user interaction or privileges to execute arbitrary code #RCE #Patch #Patch #Patch

    Post summary

    A new critical heap buffer overflow (CVE-2026-40504) in Creolabs Gravity with CVSS 9.8 is disclosed, enabling remote RCE without user interaction or privileges.

    01000161
    7.2K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-40504 — CVSS 9.8/10 ██████████ Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/YNmdR1HWvt

    Post summary

    The tweet announces a critical heap buffer overflow in Creolabs Gravity (CVE‑2026‑40504) and urges users to apply the available patch to mitigate the risk.

    1000054
    23 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-40504-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked advisory URL is referenced along with generic hashtags, but no substantive details about the CVE, exploit availability, or mitigation steps are provided.

    0000025
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40504 Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by cra… https://www.cve.org/CVERecord?id=CVE-2026-40504

    Post summary

    The message announces CVE-2026-40504, describing its heap buffer overflow nature and lack of patch or exploitation details.

    0000078
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40504 Heap Buffer Overflow in Creolabs Gravity Before 0.9.6 Enables Arbitrary Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40504

    Post summary

    The text discloses that CVE‑2026‑40504 is a heap buffer overflow in Creolabs Gravity prior to 0.9.6 that allows arbitrary code execution, but provides no exploit, patch, or evidence of active use.

    0000046
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40504: Creolabs Gravity < 0.9.6 Heap Bu... Heap corruption via string literal flooding in gravity_fiber_reassign() = instant RCE against any app evaluating untrus... https://zerodaysignal.com/vulnerability/CVE-2026-40504 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Tweet announces CVE‑2026‑40504, a heap‑corruption vulnerability in Creolabs Gravity <0.9.6 that induces immediate remote code execution, linking to further details.

    0000050
    218 followersView on X

Explore more