Ad

CVE-2026-40504

CRITICAL CVSS 4.0: 9.3
Updated Apr 17, 2026
Creolabs Gravity
Parameter Value
CVSS 9.3 (CRITICAL)
Affected Versions before 0.9.6
Type CWE-122 (Heap-based Buffer Overflow)
Vendor Creolabs Gravity
Public PoC No

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string literals at global scope. Attackers can exploit insufficient bounds checking in gravity_fiber_reassign() to corrupt heap metadata and achieve arbitrary code execution in applications that evaluate untrusted scripts.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0