PT-2026-45085 · Julia · Zeromq Jll
Published
2026-05-20
·
Updated
2026-05-20
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder allocators.hpp. The decoder static allocator could have its sized changed, but the buffer would remain the same as it is a static buffer. A remote, unauthenticated attacker who sends a crafted request to the zeromq server could trigger a buffer overflow WRITE of arbitrary data if CURVE/ZAP authentication is not enabled. The greatest impact of this flaw is to application availability, data integrity, and confidentiality.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zeromq Jll