Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11463

Опубликовано: 07 июн. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Pointer Handler. Executing a manipulation can lead to type confusion. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

A security flaw has been identified in the USCiLab Cereal library that could affect the security and stability of applications utilizing it.

Отчет

This Important vulnerability in the cereal library's Shared Pointer Handler allows a remote attacker to trigger type confusion. The publicly disclosed exploit could lead to information disclosure, data integrity issues, or a denial of service, impacting systems that process untrusted serialized data using cereal.

Меры по смягчению последствий

Since the vulnerability is triggered by processing malicious payloads, immediately restrict network access or input mechanisms that allow unauthenticated or untrusted sources to submit serialized data to the affected applications.

Дополнительная информация

Статус:

Important
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2486148cereal: USCiLab Cereal: Type confusion vulnerability in Shared Pointer Handler

EPSS

Процентиль: 24%
0.00313
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
2 месяца назад

A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Pointer Handler. Executing a manipulation can lead to type confusion. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

msrc
2 месяца назад

USCiLab Cereal Shared Pointer type confusion

CVSS3: 7.3
github
2 месяца назад

A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Pointer Handler. Executing a manipulation can lead to type confusion. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

EPSS

Процентиль: 24%
0.00313
Низкий

7.3 High

CVSS3