CVE detail
CVE-2026-3816
A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQubeParser/MSDefenderParser. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.56.0 is able to resolve this issue. The identifier of the patch is e8f1e5131535b8fd80a7b1b3085d676295fdcd41. Upgrading the affected component is recommended.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/?submit.769524vuldb.com
No excerpt available.
Exploitvuldb.comMar 9, 2026, 11:16 AM - https://vuldb.com/?id.349782vuldb.com
No excerpt available.
Exploitvuldb.comMar 9, 2026, 11:16 AM - https://vuldb.com/?ctiid.349782vuldb.com
No excerpt available.
Exploitvuldb.comMar 9, 2026, 11:16 AM No excerpt available.
Exploitgithub.comMar 9, 2026, 11:16 AMNo excerpt available.
Exploitgithub.comMar 9, 2026, 11:16 AMNo excerpt available.
Exploitgithub.comMar 9, 2026, 11:16 AMNo excerpt available.
Exploitgithub.comMar 9, 2026, 11:16 AM- https://github.com/DefectDojo/django-DefectDojo/commit/e8f1e5131535b8fd80a7b1b3085d676295fdcd41github.com
No excerpt available.
Exploitgithub.comMar 9, 2026, 11:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- henrrrychau/cve-bug-bountyHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 12, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-54890CVSS 8.2 · High
Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation.…
- CVE-2026-59532CVSS 7.5 · High
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
- CVE-2026-59531CVSS 7.5 · High
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
- CVE-2026-58662CVSS 8.7 · High
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are re…
- CVE-2026-17501CVSS 6.9 · Medium
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-t…
- CVE-2026-17500CVSS 6.9 · Medium
A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation result…