PoC Index

CVE-2026-0049

MEDIUM 6.2EPSS 0.1%

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS v3.1
6.2 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.10% chance of exploitation in the next 30 days, 1th percentile
Published
2026-04-06
Updated
2026-05-27

Proof-of-concept exploits (1)

References

Related