{"id":"CVE-2026-9521","summary":"fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input","details":"A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of input. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 5.2.5 is able to address this issue. The name of the patch is 66d16516e24893bebc1c8af52bf2fe9ad0735061. Upgrading the affected component is advised.","modified":"2026-08-12T16:09:31.371413Z","published":"2026-05-26T02:00:15.197Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9521.json","cna_assigner":"VulDB","cwe_ids":["CWE-1287","CWE-20"]},"references":[{"type":"WEB","url":"https://github.com/fraillt/bitsery/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9521.json"},{"type":"ADVISORY","url":"https://github.com/fraillt/bitsery/blob/master/CHANGELOG.md#525-2025-10-09"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9521"},{"type":"ADVISORY","url":"https://vuldb.com/submit/814457"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/365541"},{"type":"REPORT","url":"https://vuldb.com/vuln/365541/cti"},{"type":"FIX","url":"https://github.com/fraillt/bitsery/commit/66d16516e24893bebc1c8af52bf2fe9ad0735061"},{"type":"FIX","url":"https://github.com/fraillt/bitsery/releases/tag/v5.2.5"},{"type":"EVIDENCE","url":"https://gist.github.com/TrebledJ/750abc64a826f19dd2d6774724629b71"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fraillt/bitsery","events":[{"introduced":"8a00183c8016b87033861b325c2093f08c80ad02"},{"fixed":"66d16516e24893bebc1c8af52bf2fe9ad0735061"},{"fixed":"9bebfd4911b8ef52c5a67754ccb87a8fd5223414"}],"database_specific":{"extracted_events":[{"introduced":"5.2.0"},{"last_affected":"5.2.0"},{"introduced":"5.2.1"},{"last_affected":"5.2.1"},{"introduced":"5.2.2"},{"last_affected":"5.2.2"},{"introduced":"5.2.3"},{"last_affected":"5.2.3"},{"introduced":"5.2.4"},{"last_affected":"5.2.4"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["5.2.0","5.2.1","5.2.2","5.2.3","5.2.4","v5.2.4","v5.2.3","v5.2.2","v5.2.1","v5.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9521.json","vanir_signatures_modified":"2026-08-12T16:09:31Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/fraillt/bitsery/commit/66d16516e24893bebc1c8af52bf2fe9ad0735061","target":{"file":"include/bitsery/ext/pointer.h"},"deprecated":false,"digest":{"line_hashes":["84898255754592973667273245349040609551","255616915660356963139871415375103922546","226531567102020966706637728664940355991","331849131793873403456013363991202953297","76344211797538854095265519212792600461","255672745053429325963292863915847160402","54089603585520039939150775488662096161","54170835533579169781171554376275436882","263037895152559941545924969174035680678","161822118536186000859728410459719766948","203254544686534454864321576468004462509","143832083438091089480817184888275966809","310528207552236064839872689860986810927","267531423717967103995943594216576612730","291344158837575852168175616648717806040","205699097570268821515591530137239269450","280904793591976780597607465765429537172","318098222094382005822669358049947232850","43787528879350076656145428257496593958","158158938999398700848429212926139720654","286269673222001586945886540003942424232","179768721663998696941789002224659793397","334893143543877588011458692942449604637","185496020860675808250795083906179160324","263516150481262094456755861948890477460","21911155122216029216371755847682130276","44605751325408183885239090408458944990","197558010054546018454602714149214471603","148096768874498409114282131398679324726","219019044004398956920502578433942800160","120050053672284452132593671235845534557","277836035307141204089278680983802186407","197339448693603699712813175521799446178","41327893819884206741247889443384157659","234367674879760456903442718854823060852","197963368333653536187060770993491090969","67153601428469608110348330067822193199","60949124142249445815914306652605272239","315421103436128025328746499970131632023","199406048967766718817035699699506732060","291734816672117274992798358690674597377","294589812795057111584357893911400911634","213468256703559200874621780601591560173","275217244371985390720182426274835685282","336532848834004997078842300900650800218","90002928758522128251247985069370371895","290992310642095648046124443827118608188","101848479272470218618771535446022594087","261882610162708650102574654042898189827","167139655827675838591300535773623606232","198665524454283542549999835651786470893","220844248354798359986646793801587425176","187029991728720133805300628213136591856","227262297564205824951655317271404550458","67363364618283005991875171513444668268","272999274287035193807307412467837984191","146330975891987685188776849280408839010","172455729555097150448634035708862709472","232805027475710283887017257563479439460","98938870516292322254116748788705432161","273349341676959888204637163177970723829","75481963912755975336135308784193590902","8146422027128593440387068392993540885","201918806385846899859101557779717451620","77396240476394179957175798635382212343","118534045253989144839591359468666517995","63917147112950550716965965151975938276","129058054685327769817564414054187564389","41460867135287555646122015567344324304","235237469606573479592562228070339839322","264987709332885003291063760049042348454","302860930351361407203650761743572670880"],"threshold":0.9},"id":"CVE-2026-9521-1e20fb51","signature_type":"Line"},{"target":{"file":"tests/serialization_ext_std_smart_ptr.cpp"},"deprecated":false,"digest":{"line_hashes":["89357550947682023365448482883077759344","333893465537953641261143514518515862286","279878023513570786630657465618193210783","51739647633858020403464354436681290449","111289938963888736902436879169744433117","251404501350589058517308060226583689703","230624872395262477369431096596320585768","34550222118498472132107497294217121592","95238372787119048255206615872398603820"],"threshold":0.9},"id":"CVE-2026-9521-5718d8a4","signature_type":"Line","signature_version":"v1","source":"https://github.com/fraillt/bitsery/commit/66d16516e24893bebc1c8af52bf2fe9ad0735061"},{"source":"https://github.com/fraillt/bitsery/commit/66d16516e24893bebc1c8af52bf2fe9ad0735061","target":{"file":"include/bitsery/ext/utils/polymorphism_utils.h"},"deprecated":false,"digest":{"line_hashes":["313263478876547246306780949145715805465","238045093066592442063236055931367020584","62965413948862252666609624360511419799","46835429277239255146178424172708890969","219331985478872130114966628947362901663","310313053428075610850911709503068070755","97578013883929609246604120442773403000","305333265627568370274339920878715593635","212273946990322897671012279237623782371","217862104150508001789533114410470864494","91225038731966856385743679820089179236","91499920708874134475826424044157896642","57029071116829302903440277506551108843","208930097007379611653302448905916575207","169868835640853717513840573668774573266","215961837940963085701385215849402037421","329865211181940092901137880297645054476","334465051272237269130004007873880853022","277886640919727830492885092684472870600","27769339615108721224319100648307281197","325567181879966446262890407483759574406","8112414652800445304727256492877199093","276839907582522782635030580558099376230","263993187427797109274969835457301646520","208930097007379611653302448905916575207","252011216422670613752245011007847947373","182066479015960021731749098858284068294","274979295482270838697719472278409690925","94179067750132065466519744637776619504","230856524708559504445652024889089838519","79500000458778706570907138849382566032","81383012967986539406855469571042453516","214344805587819190580728081147289199485","104188342022221057848024506398751958528","212053497896889937639564715005613534755","97659014891145814829724074739420338038","181076613169774009986341691162582485758","331900432413405205253114294866286749266","227171569079986141506152023525400763928","213339857911811497419728288249866077413","263993187427797109274969835457301646520","208930097007379611653302448905916575207","169868835640853717513840573668774573266","277683700761093135228805071996110399855","175556676264829165261278058283225181753","67780191586029594825621923290035674096","331476957050124020660390756454405389488","82707942212078996357519414561922316405","312169122864174434822362098673035180938","271028443021139669503771084221426262649","25071228546905451843847831361680338478","49938001860988433836685749155503596059","130484499768427652967270593173841681657","3334023718032042201530903407853072569","330066996360889608659888529710877031892","317095327071993305289432195667985791132","229493746052735406307363877869644456388","12649556075817984136737780774615888706","12288438248317611378844992368423429259","91372948030220026572622605132079222724","332740577048185175897794915865664654013","23072350902620584056850533287146762473","152360829735442260068304909649838724449","95290780753106896687766503052352988535","266268747319630164439623075002173048775","235181264654359910367805030130342029667","236722139339843108090323173178222801249","123368623188234646358217356480277737203","197383705516930743782780027527369162069","135092535065623292677911805096205239646","281294606260201348415720899406804807530","150353584964589685494055612885591204187","183091185099359257544911926148261978610","190873182146611186059627410853380843320","258387226339114486355832138730342344158","17310453708175146610713317223444896002","184252492255991938353784582844522930622","261538703485897079809985257045390480915","281611903085981227557849851896860562644","124258546217672411648192794989019097423","192941216878259424067897351436152427913","297602386143162635831664633464179787914","186001020158197207781702346898664852780","327351677851121387837215602791669191523","54258850154665613923707751740333754158","187332019792659634182014841700592736280","14074714828986183775474144395384874332","22650050353255640268247126868541324776","112696083650550116401783016326282695173","222192074491030780260861529931916062599","47308839066324874706573065186792545466","226362892916702506511565942461979464225","336271044874528927399369113562108040060","328572391682816616176045497982033670665","60557398996025184103618289325730349958","85357299940334922299561802033188897853","142122007784393244340369795859911271504"],"threshold":0.9},"id":"CVE-2026-9521-5c1bfa6c","signature_type":"Line","signature_version":"v1"},{"digest":{"line_hashes":["140807797764838229962066568956799678246","34234695022847192945905295004058836603","269237176974454993643521919834099667684","37306280481448866528617053864419064376","78044919843943046962007268791227258835","317806653514325644023843727802986740156","140232437148233302565575075461784872609","118321435212214057147469176960835303450","190096908010913406107475611144271106631","163838352939912596852827540996238486567","57930292409844898532863628364053423408","278477647023352841793451827365922639385","174963482609400128494441973437053148852","35389111390246656512846427577400603588","86743726680945368183001593637458568289","282019684230197146159079350312265147385","183226948552341292961189656629390185024","298766467074786169793906025374695035064","320632307140444982715077370624585147114","312256089371761837529157240271989726246","186570502240323729971305270094243478984","171528426810277689598998817848469402148","7733827609777716117715416308002344433","274299406287098254067677241678116904208","114716173445702817010636616637364183146","206588128791309671144698078943288596267","183576865742303770317723003331925670378","193073482553173216588410245440864501764","109975148766590533622058408742951889643","264915721871292789523400393010452965131","331596017643107849738080432826280491576","138163883427675731942069787719759193656","203853209318809585653640347992562828693","298142986223863638144678748704989067072","267001516550521296819471841992525507376","132771028813154654043139554032004406200","232251820801698373757312528777809191580","212456202639374831898993770249710700701","184116419653933399482352608314543056925","265104168202945850906276050388016617207","5233390835372663922199898978207844763","97613364623092466611702686961288049251","115289088143611061833212192392835090958","212079759682484329767190181276576923775","336672488622554559093143687918435395283","271267655833635809272811268473257483915","185999562265881612634726407966746940327","256502964678998902213148081854433501118","6558489477362603302042074566712662323","159010031255896880317972563916163690059","289209042204792528853152846787042153751","45706299250384473795501797802898095836","316544378614779678081944070807563868762","101739946602209883345762293357354484780","61750264066192376995709626643338673227","32215871265048705259307067009024417206","23580990934558855875538925650767365119","185999562265881612634726407966746940327","151580893523822191570882348106251999322","1105842564344829426012325223477119280"],"threshold":0.9},"id":"CVE-2026-9521-842fa93c","signature_type":"Line","signature_version":"v1","source":"https://github.com/fraillt/bitsery/commit/66d16516e24893bebc1c8af52bf2fe9ad0735061","target":{"file":"include/bitsery/ext/utils/pointer_utils.h"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["22255568110966025225745817468705910983","80833475300622767351717373311258705020","124711680872966450592790221590500300516","57926267431803239844136403239290572278","317501515930696874781716348259025391496","212135846125783863558258215355703703133"],"threshold":0.9},"id":"CVE-2026-9521-cf062703","signature_type":"Line","signature_version":"v1","source":"https://github.com/fraillt/bitsery/commit/66d16516e24893bebc1c8af52bf2fe9ad0735061","target":{"file":"include/bitsery/ext/std_smart_ptr.h"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}