HIGHVulnerability

CVE-2026-90556

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.

Properties

severity
HIGH
score
7.8
cve_id
CVE-2026-90556
signal_observed_at
2026-09-21T23:07:07+00:00
vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
published_at
2026-09-12T18:16:44.193
last_modified
2026-09-18T18:18:00.080

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Heap-based Buffer Overflow

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90556 — Ninja Signal Threat Intelligence | Ninja Signal