PT-2026-45085 · Julia · Zeromq Jll

Published

2026-05-20

·

Updated

2026-05-20

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder allocators.hpp. The decoder static allocator could have its sized changed, but the buffer would remain the same as it is a static buffer. A remote, unauthenticated attacker who sends a crafted request to the zeromq server could trigger a buffer overflow WRITE of arbitrary data if CURVE/ZAP authentication is not enabled. The greatest impact of this flaw is to application availability, data integrity, and confidentiality.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-515

Affected Products

Zeromq Jll