CVE-2026-68911

Published: Set 29, 2026 Last Modified: Set 29, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,7
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11.

409

Improper Handling of Highly Compressed Data (Data Amplification)

Incomplete
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Amplification Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory)
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/nicotine-plus/nicotine-plus/commit/61de347fbaaab02eae1606df4…
https://github.com/nicotine-plus/nicotine-plus/pull/3646
https://github.com/nicotine-plus/nicotine-plus/releases/tag/3.3.11
https://github.com/nicotine-plus/nicotine-plus/security/advisories/GHSA-8w4c-p7…