{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gravity--0.9.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:marcobambini:gravity:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90715"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Gravity (\u003c= 0.9.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["marcobambini"],"content_html":"\u003cp\u003eA security vulnerability has been identified in the Gravity library, specifically within the udp json-parser component located in src/utils/gravity_json.c. The flaw, tracked as CVE-2026-90715, affects all versions up to and including 0.9.7. The vulnerability stems from an integer overflow condition that can be triggered remotely. If successfully exploited, the vulnerability may allow an attacker to crash the host application or potentially achieve arbitrary code execution, depending on the memory layout of the surrounding process. Public disclosure of exploitation vectors has been observed, making immediate remediation necessary for systems utilizing the Gravity library for JSON processing.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects applications relying on the Gravity library for processing JSON data over UDP. Successful exploitation can result in a denial of service (application crash) or potential compromise of the host system. Given the remote accessibility of the attack vector, organizations running software that integrates Gravity version 0.9.7 or earlier are at risk of remote exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Gravity library to version 0.9.8 or later immediately to incorporate the patch (commit 9b337c3eae5833c3956bed1fc01c21c14fd443f2).\u003c/li\u003e\n\u003cli\u003eReview internal applications for dependencies on the marcobambini Gravity library and prioritize patching for any internet-facing services or services that process untrusted network input.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T13:33:55Z","date_published":"2026-09-14T13:33:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gravity-integer-overflow/","summary":"An integer overflow vulnerability (CVE-2026-90715) in the Gravity library's udp json-parser allows remote attackers to trigger application crashes or potential arbitrary code execution.","title":"Integer Overflow Vulnerability in Gravity JSON Parser","url":"https://feed.craftedsignal.io/briefs/2026-09-gravity-integer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Gravity (\u003c= 0.9.7)","version":"https://jsonfeed.org/version/1.1"}