Description
A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 0.9.8 mitigates this issue. The name of the patch is 9b337c3eae5833c3956bed1fc01c21c14fd443f2. Upgrading the affected component is recommended.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote integer overflow in Gravity UDP JSON parser
Action: Upgrade
AI Analysis

Impact

Gravity’s UDP JSON parser can be tricked into performing an integer overflow when processing specially crafted JSON data received over UDP, an error associated with both CWE-190 (Integer Overflow or Wraparound) and CWE-189 (Numeric Truncation or Overflows). This overflow can destabilise the parsing routine, potentially corrupting memory or causing the application to crash. The vulnerability is exploitable from a remote location; an attacker can craft packets to trigger it without needing local access. The primary impact is a moderate loss of integrity and availability for systems running unpatched Gravity versions, with the possibility of further exploitation depending on specific environmental factors.

Affected Systems

The Gravity project by marcobambini, versions up to and including 0.9.7, are vulnerable. Releasing the 0.9.8 update fixes the issue, as identified by the commit 9b337c3eae5833c3956bed1fc01c21c14fd443f2. All other versions of Gravity that include earlier or modified code without this patch remain exposed.

Risk and Exploitability

The CVSS score of 6.9 categorises the flaw as medium severity. No EPSS score is available, so there is no concrete data on exploitation likelihood, and the vulnerability is vector is remote, leveraging malformed UDP packets that are parsed by the vulnerable JSON routine. An attacker could induce crashes, denial‑of‑service conditions or, depending on system configuration, potentially more damaging memory corruption. Organizations should consider the CVSS rating and known public exploitation when prioritising remediation.

Generated by OpenCVE AI on September 15, 2026 at 14:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Gravity to version 0.9.8 or later, which contains the integer‑overflow fix identified by commit 9b337c3eae5833c3956bed1fc01c21c14fd443f2.
  • If an upgrade cannot be performed immediately, apply network controls to restrict or block UDP traffic destined for the Gravity service to mitigate the possibility of exploitation.
  • Apply any subsequent security patches released by the Gravity project that address integer‑overflow or related parsing issues.

Generated by OpenCVE AI on September 15, 2026 at 14:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 0.9.8 mitigates this issue. The name of the patch is 9b337c3eae5833c3956bed1fc01c21c14fd443f2. Upgrading the affected component is recommended.
Title marcobambini Gravity udp json-parser gravity_json.c integer overflow
First Time appeared Marcobambini
Marcobambini gravity
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:marcobambini:gravity:*:*:*:*:*:*:*:*
Vendors & Products Marcobambini
Marcobambini gravity
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Marcobambini Gravity
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:38:30.394Z

Reserved: 2026-09-13T09:53:06.509Z

Link: CVE-2026-90715

cve-icon Vulnrichment

Updated: 2026-09-14T15:38:22.894Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:19:30.080

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses