← back
CVE-2026-1489

Glib: glib: memory corruption via integer overflow in unicode case conversion

CVSS 5.4 MEDIUMEPSS 0.3%CWE-787
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
27 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →