Skip to main content

CVE-2025-13601

CVE Details

Visit the official vulnerability details page for CVE-2025-13601 to learn more.

Initial Publication

11/26/2025

Last Update

02/19/2026

Third Party Dependency

glib2

NIST CVE Summary

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.

CVE Severity

7.7

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Modified

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
0.7.1⚠️ Impacted⚠️ Impacted
0.6.6⚠️ Impacted⚠️ Impacted
0.5.11⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.