Medium severity6.3NVD Advisory· Published Sep 14, 2026
CVE-2026-90714
CVE-2026-90714
Description
A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the file src/utils/gravity_json.c of the component JSON parser. This manipulation causes memory corruption. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.8 is sufficient to resolve this issue. Patch name: 9b337c3eae5833c3956bed1fc01c21c14fd443f2. It is suggested to upgrade the affected component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
8- github.com/marcobambini/gravity/issues/448nvd
- github.com/marcobambini/gravity/pull/451nvd
- github.com/marcobambini/gravity/releases/tag/0.9.8nvd
- github.com/sthagen/marcobambini-gravity/commit/9b337c3eae5833c3956bed1fc01c21c14fd443f2nvd
- vuldb.com/cve/CVE-2026-90714nvd
- vuldb.com/submit/919185nvd
- vuldb.com/vuln/403268nvd
- vuldb.com/vuln/403268/ctinvd
News mentions
0No linked articles in our index yet.