{"id":"CVE-2024-26134","summary":"CBOR2 decoder has potential buffer overflow","details":"cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object. Version 5.6.2 contains a patch for this issue.","aliases":["GHSA-375g-39jq-vq7m","PYSEC-2024-155"],"modified":"2026-08-12T15:15:55.362032Z","published":"2024-02-19T22:13:47.173Z","related":["SUSE-SU-2025:21168-1","openSUSE-SU-2025:14733-1","openSUSE-SU-2025:20133-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-120"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26134.json"},"references":[{"type":"WEB","url":"https://github.com/agronholm/cbor2/releases/tag/5.6.2"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BT42VXZMMMCSSHMA65KKPOZCXJEYHNR5/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GX524ZG2XJWFV37UQKQ4LWIH4UICSGEQ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWC3VU6YV6EXKCSX5GTKWLBZIDIJNQJY/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26134.json"},{"type":"ADVISORY","url":"https://github.com/agronholm/cbor2/security/advisories/GHSA-375g-39jq-vq7m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26134"},{"type":"FIX","url":"https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542"},{"type":"FIX","url":"https://github.com/agronholm/cbor2/commit/4de6991ba29bf2290d7b9d83525eda7d021873df"},{"type":"FIX","url":"https://github.com/agronholm/cbor2/pull/204"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/agronholm/cbor2","events":[{"introduced":"f31dff18b8f851e58bf589ba742a3c79a6f33e20"},{"fixed":"21e0debcf8ddf9d6034a3bb0d01477f3b855e166"},{"fixed":"387755eacf0be35591a478d3c67fe10618a6d542"},{"fixed":"4de6991ba29bf2290d7b9d83525eda7d021873df"}],"database_specific":{"cpe":"cpe:2.3:a:agronholm:cbor2:*:*:*:*:*:python:*:*","extracted_events":[{"introduced":"5.5.1"},{"fixed":"5.6.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["5.6.1","5.6.0","5.5.1"],"database_specific":{"vanir_signatures_modified":"2026-08-12T15:15:55Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"42559882691512573945981785976818224862","length":1118},"id":"CVE-2024-26134-1c4d7424","signature_type":"Function","signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/4de6991ba29bf2290d7b9d83525eda7d021873df","target":{"file":"source/tags.c","function":"CBORTag_hash"}},{"signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542","target":{"file":"source/decoder.c","function":"decode_bytestring"},"deprecated":false,"digest":{"function_hash":"34367670186001808182596188036311348824","length":529},"id":"CVE-2024-26134-3648b83c","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["299071751757982641627657448278086797614","21532027677011166273953640366535827196","66618904500541504277316461838357043036","291386074458460040375946121630730779054"],"threshold":0.9},"id":"CVE-2024-26134-688eeed3","signature_type":"Line","signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/4de6991ba29bf2290d7b9d83525eda7d021873df","target":{"file":"source/tags.c"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542","target":{"file":"source/decoder.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["186111473807463969390987066092794274248","265584218305771273230253096649436885128","295595637029948756081875806440024716582","130609369903819730223369084970701021907","302647030036630519888736998580827256739","172512258574298384702944617456279261741","309026526656385395465025153819608080466","21628653664904818964272987298894413281","96398271689325962071843913064404982201","286375868443472051923108030793639130937","83418368762135674575350772888978606456","50092288655626516815961162838644948342","184872207504596093967585283953686486390","171350721112196223193637577408315157297","86068577229277512504275962750508531587","20061553470929506234589744284146137608","236655068478303813748634286226520002982","12699906497546501752194502722448998720","219015986041799598605341437289898174760","250540368793546969837302865471310977494","296164759189210814358473432668607028391","175198856259206220479424845474723491638","6309195051118151650356582204696100110","131961870601446005062250136994488044844","251387453817777364260049761597202712209","51346394501876660769977439643044886222","269645374498175144934705434741360449346","109589278738508545877574183453918534192","24417301757260860728458294491119013399","312787814786835793742967170787572248295","311538882733136691567571483595542772046","154115011325848673464942212557692141040","29417917360734070361105137290212714137","37594227032768694697996303779772735550","121307991355830401804605748237294593198","84234095629794150811311221505684009599","228088835882952787860166531702520654918","329316508592033434139193538286277143384","321514650351157150237859765439930662326","254535891827861064645659693964812925215","195090007019611042074697932101807508950","106365305761658255204938840879469426414","185850675859003552635521044669085831905","209427630195832386725065269020505483095","24883326294023588537192103576046317546","154027890858244746895656519028335514691","196403671641811722598654748354608814827","129988442689146780520839888076980699756","289525994334053879286871056633350383752","181437679744255422324498587193780123444","86087407611800883675718663285505696907","232301301464286148890352243749878306538","84342046321563728281652369643189075891","86688433828578556774365427117957038239","94945918937594420350539636145105761191","330597637914388295920174459561027558086","304943769546058821632299506873294410453","255554820562100079731795059824032100659","166138883707178142584063758080862306837","62772670870091139556520374482730075762","103060982983518797736230374806977701084","335028465364120989086234164944010853392","261665863199837844764933486803372249023","291824472632532813721479460801668095047","151932890043933343815160537466572244375","104670342116230824153428054505298101712","164650233386770860149752390297923417909","195090007019611042074697932101807508950","306154579398359337957083594831750894858","252450547161964688994881726190296363094","131572783342480953599167640055180209765","334134418879614409598441689172700703458","215250044097451588865607458948202297680","32263122633366478789580213638521714662","228252757339179303127734467511219219712","177902602828252504979766358074005927778","181437679744255422324498587193780123444"]},"id":"CVE-2024-26134-73288b7b"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["99960288471367051203772129741234537543","199154807751276266509756474281216737338","263645717488197801313616377047701352533","196721406994596149037264112164161764851"]},"id":"CVE-2024-26134-75b8c657","signature_type":"Line","signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542","target":{"file":"source/tags.c"}},{"deprecated":false,"digest":{"function_hash":"163671374791229368363776781847734576071","length":335},"id":"CVE-2024-26134-819cc3b2","signature_type":"Function","signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542","target":{"file":"source/decoder.c","function":"decode_definite_bytestring"}},{"target":{"file":"source/decoder.c","function":"fp_read"},"deprecated":false,"digest":{"function_hash":"145655655782609998736895600392968788371","length":607},"id":"CVE-2024-26134-9e74915d","signature_type":"Function","signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542"},{"signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542","target":{"file":"source/decoder.c","function":"decode_definite_string"},"deprecated":false,"digest":{"function_hash":"115790608133277478357095825320282788385","length":412},"id":"CVE-2024-26134-b935501c","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542","target":{"file":"source/decoder.c","function":"decode_string"},"deprecated":false,"digest":{"function_hash":"183523165108085540778244965699537002028","length":525},"id":"CVE-2024-26134-c6b15273"},{"deprecated":false,"digest":{"function_hash":"263103292866399598934480346874748866113","length":1116},"id":"CVE-2024-26134-f3b97445","signature_type":"Function","signature_version":"v1","source":"https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542","target":{"function":"CBORTag_hash","file":"source/tags.c"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26134.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}