CVE-2026-68911 Details
Description
Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11.
A denial-of-service vulnerability has been identified in Nicotine+ versions prior to 3.3.11. The issue arises when a modified remote client sends zlib-compressed peer messages that include a decompression bomb. This type of message can cause the recipient's operating system to run out of available memory. The vulnerability has been addressed in version 3.3.11 by implementing a maximum size limit for uncompressed messages, discarding any that exceed this limit.
Users are advised to upgrade to Nicotine+ version 3.3.11 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nicotine-plus/nicotine-plus/commit/61de347fbaaab02eae1606df4f95d9dc17066d4c | [email protected] | Source CodeVendor |
| https://github.com/nicotine-plus/nicotine-plus/pull/3646 | [email protected] | Issue TrackingVendor |
| https://github.com/nicotine-plus/nicotine-plus/releases/tag/3.3.11 | [email protected] | Release NotesVendor |
| https://github.com/nicotine-plus/nicotine-plus/security/advisories/GHSA-8w4c-p7mj-g886 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-409 | Improper Handling of Highly Compressed Data (Data Amplification) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Nicotine+ | < 3.3.11 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion