PULSE
FEED
ransombyod reclama a Royal Selangor · MY · Manufacturingransomlamashtu reclama a Fluge Audiovisuales · ES · Otherransomlamashtu reclama a Bender Tribunenbau · DE · Manufacturingransomlamashtu reclama a TRANS LOGROÑO SOCIEDAD ANONIMA · ES · Transportationransomlamashtu reclama a Grupo Industrial Tauro · MX · Manufacturingransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransombyod reclama a Royal Selangor · MY · Manufacturingransomlamashtu reclama a Fluge Audiovisuales · ES · Otherransomlamashtu reclama a Bender Tribunenbau · DE · Manufacturingransomlamashtu reclama a TRANS LOGROÑO SOCIEDAD ANONIMA · ES · Transportationransomlamashtu reclama a Grupo Industrial Tauro · MX · Manufacturingransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturing
← All CVEs
CVE WatchSep 29, 2026

CVE-2026-68911

Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compr

CVSS

—

No CVSS

EPSS

0.3%

p21

KEV

—

Exploit Today

6

0-100

Published: Sep 29, 2026 · Last modified: Sep 29, 2026 · CWE-409

EPSS · 30d
0.3%EPSS · 30 days0.3%
2026-09-302026-10-04
Technical description

Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-66054—
34.6%
——10Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.2d
CVE-2026-94637—
34.6%
——10Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.3d
CVE-2026-94636—
34.6%
——10Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.3d
CVE-2026-1032627.5 HIG
42.5%
——13Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.4d
CVE-2026-86104—
27.0%
——8An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.6d
CVE-2026-925736.5 MED
19.3%
——6Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.10d