CVE-2026-24811

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root.
Configurations

Configuration 1 (hide)

cpe:2.3:a:root:root:*:*:*:*:*:*:*:*

History

19 Feb 2026, 17:24

Type Values Removed Values Added
References
  • () https://root.cern/blog/recent-common-vulnerabilities-when-does-ROOT-need-to-be-updated/ -

17 Feb 2026, 19:58

Type Values Removed Values Added
CPE cpe:2.3:a:root:root:*:*:*:*:*:*:*:*
First Time Root root
Root
References () https://github.com/root-project/root/pull/18526 - () https://github.com/root-project/root/pull/18526 - Issue Tracking, Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

27 Jan 2026, 15:15

Type Values Removed Values Added
CWE CWE-119
CWE-20
CWE-125
CWE-787

27 Jan 2026, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 09:15

Updated : 2026-02-19 17:24


NVD link : CVE-2026-24811

Mitre link : CVE-2026-24811

CVE.ORG link : CVE-2026-24811


JSON object : View

Products Affected

root

  • root
CWE
CWE-20

Improper Input Validation

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read

CWE-787

Out-of-bounds Write