{"id":"CVE-2026-24793","summary":"A heap-based buffer over-read or buffer overflow vulnerability in azerothcore/azerothcore-wotlk","details":"Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in azerothcore azerothcore-wotlk (deps/zlib modules). This vulnerability is associated with program files inflate.C.\n\nThis issue affects azerothcore-wotlk: through v4.0.0.","modified":"2026-08-12T03:51:17.513485205Z","published":"2026-01-27T08:19:41.350Z","database_specific":{"cna_assigner":"GovTech CSG","cwe_ids":["CWE-120","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24793.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24793.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24793"},{"type":"FIX","url":"https://github.com/azerothcore/azerothcore-wotlk/pull/21599"},{"type":"PACKAGE","url":"https://github.com/azerothcore/azerothcore-wotlk"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/azerothcore/azerothcore-wotlk","events":[{"introduced":"0"},{"last_affected":"283ffb20e83f5302e6feccc4adaa288ade9398b8"}],"database_specific":{"cpe":"cpe:2.3:a:azerothcore:azerothcore:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"v4.0.0"},{"last_affected":"4.0.0"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["v4.0.0","v3.0.0","v3.0.0-dev","v2.0.0","v1.0-dev","1.0-dev","v0.5","0.5","v0.1.1","0.1.1","v0.1","0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24793.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/V:C/RE:L/U:Red"}]}