<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Gravity (&lt;= 0.9.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gravity--0.9.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 13:33:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gravity--0.9.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Integer Overflow Vulnerability in Gravity JSON Parser</title><link>https://feed.craftedsignal.io/briefs/2026-09-gravity-integer-overflow/</link><pubDate>Mon, 14 Sep 2026 13:33:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-gravity-integer-overflow/</guid><description>An integer overflow vulnerability (CVE-2026-90715) in the Gravity library's udp json-parser allows remote attackers to trigger application crashes or potential arbitrary code execution.</description><content:encoded><![CDATA[<p>A security vulnerability has been identified in the Gravity library, specifically within the udp json-parser component located in src/utils/gravity_json.c. The flaw, tracked as CVE-2026-90715, affects all versions up to and including 0.9.7. The vulnerability stems from an integer overflow condition that can be triggered remotely. If successfully exploited, the vulnerability may allow an attacker to crash the host application or potentially achieve arbitrary code execution, depending on the memory layout of the surrounding process. Public disclosure of exploitation vectors has been observed, making immediate remediation necessary for systems utilizing the Gravity library for JSON processing.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects applications relying on the Gravity library for processing JSON data over UDP. Successful exploitation can result in a denial of service (application crash) or potential compromise of the host system. Given the remote accessibility of the attack vector, organizations running software that integrates Gravity version 0.9.7 or earlier are at risk of remote exploitation.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the Gravity library to version 0.9.8 or later immediately to incorporate the patch (commit 9b337c3eae5833c3956bed1fc01c21c14fd443f2).</li>
<li>Review internal applications for dependencies on the marcobambini Gravity library and prioritize patching for any internet-facing services or services that process untrusted network input.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>