CVE-2026-85091
CVE Details
Visit the official vulnerability details page for CVE-2026-85091 to learn more.
Initial Publication
09/03/2026
Last Update
09/09/2026
Third Party Dependency
zlib1g
NIST CVE Summary
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.
CVE Severity
Our Official Summary
Investigation is ongoing to determine how this vulnerability affects our products.
Status
Awaiting Analysis
Affected Products & Versions
| Version | PaletteAI | PaletteAI VerteX |
|---|---|---|
| 1.3.2 | ⚠️ Impacted | ⚠️ Impacted |
| 1.2.2 | ⚠️ Impacted | ⚠️ Impacted |
| 1.1.8 | ⚠️ Impacted | ⚠️ Impacted |
Revision History
No revisions available.