OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-95509

HIGH · CVSS 8.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability arises from incorrect buffer size calculations when handling Latin-1 characters in String.arg(), leading to potential out-of-bounds reading. This flaw can be exploited to access sensitive data or execute arbitrary code, posing a significant risk to applications that rely on string formatting. Organizations utilizing affected products should prioritize patching this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-95509
Severity
HIGH
CVSS
8.8
EPSS
0.31%

Original NVD Description

Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.