CVE-2026-68911
HIGH
8,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11.
409
Improper Handling of Highly Compressed Data (Data Amplification)
IncompleteCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Amplification
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Applicable Platforms
All platforms may be affected
https://github.com/nicotine-plus/nicotine-plus/commit/61de347fbaaab02eae1606df4…
https://github.com/nicotine-plus/nicotine-plus/pull/3646
https://github.com/nicotine-plus/nicotine-plus/releases/tag/3.3.11
https://github.com/nicotine-plus/nicotine-plus/security/advisories/GHSA-8w4c-p7…