OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-96280

HIGH · CVSS 7.5 EPSS 0.60% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability arises from the OCI delta stream parser, which improperly handles size values, leading to heap buffer overflows on 32-bit systems. This flaw can be exploited by an attacker controlling an OCI registry to craft malicious delta streams, potentially allowing for code execution during flatpak installations or updates. Organizations using flatpak on 32-bit systems should prioritize addressing this issue to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96280
Severity
HIGH
CVSS
7.5
EPSS
0.60%

Original NVD Description

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.