CVE-2026-24814 CRITICAL

CVE-2026-24814: A integer overflow in swoole/swoole-src

Vendor Swoole
Product swoole-src
Weakness CWE-190
Published January 27, 2026
Last update January 27, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/V:C/RE:L/U:Red

What the vulnerability does

01Description

Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files sds.C. This issue affects swoole-src: before 6.0.2.

Key dates

02Disclosure timeline

January 27, 2026 CVE published
January 27, 2026 Record updated