LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-26209

agronholm · cbor2

Published
CVSS7.5
Severityhigh
WeaknessCWE-674
ExploitedNot in CISA KEV

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Versions prior to 5.9.0 are vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding deeply nested CBOR structures. This vulnerability affects both the pure Python implementation and the C extension `_cbor2`. The C extension relies on Python's internal recursion limits `Py_EnterRecursiveCall` rather than a data-driven depth limit, meaning it still raises `RecursionError` and crashes the worker process when the limit is hit. While the library handles moderate nesting levels, it lacks a hard depth limit. An attacker can supply a crafted CBOR payloa

References

← Back to the CVE Tracker

Our coverage of CVE-2026-26209

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-26209.