CVE-2026-24819
CVE-2026-24819 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1325.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.3)
- EPSS exploit prediction: 0% (36th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-4799
- Weakness: CWE-1325
- Published:
- Last modified:
Description
Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/foxinmy/weixin4j/util modules). This vulnerability is associated with program files CharArrayBuffer.Java, ClassUtil.Java. This issue affects weixin4j.
Frequently asked questions
- What is CVE-2026-24819?
- Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/foxinmy/weixin4j/util modules). This vulnerability is associated with program files CharArrayBuffer.Java, ClassUtil.Java. This issue affects weixin4j.
- How severe is CVE-2026-24819?
- CVE-2026-24819 has a CVSS 4.0 base score of 6.3, rated medium severity.
- Is CVE-2026-24819 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (36th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-24819?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-24819 have an EU (EUVD) identifier?
- Yes. CVE-2026-24819 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-4799.
- When was CVE-2026-24819 published?
- CVE-2026-24819 was published on 2026-01-27 and last updated on 2026-06-17.
References
Other CWE-1325 vulnerabilities
- CVE-2024-27796 — High (CVSS 7.8): The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS…
- CVE-2026-34183 — High (CVSS 7.5): Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing…
- CVE-2025-2240 — High (CVSS 7.5): A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This…
- CVE-2026-54081 — Medium (CVSS 6.9): veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a…
- CVE-2026-54080 — Medium (CVSS 6.9): veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a…
- CVE-2026-18772 — Medium (CVSS 6.5): Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data…