{"id":"AZL-105906","summary":"CVE-2026-63209 affecting package telegraf 1.31.0-33","details":"compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7.","modified":"2026-10-03T14:16:40.871788234Z","published":"2026-09-29T15:17:27Z","upstream":["CVE-2026-63209"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63209"}],"affected":[{"package":{"name":"telegraf","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/telegraf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.31.0-33"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105906.json"}}],"schema_version":"1.9.0"}