CVE-2026-50593: CWE-191 Integer Underflow (Wrap or Wraparound) in Graphite project Graphite
Graphite versions prior to 1.3.15 contain an integer underflow vulnerability that leads to an out-of-bounds write. This occurs because the 'slotat' function does not properly validate that an offset is within the allowed slot-map range. The vulnerability has a high severity with a CVSS score of 7.3.
AI Analysis
Technical Summary
CVE-2026-50593 is an integer underflow vulnerability in the Graphite project affecting versions before 1.3.15. The issue arises from the 'slotat' function failing to ensure that an offset is within the valid slot-map range, which can cause an integer underflow and result in an out-of-bounds write. This can impact confidentiality, integrity, and availability as indicated by the CVSS vector (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H). No official patch or remediation level is currently documented.
Potential Impact
Successful exploitation can lead to an out-of-bounds write, potentially allowing an attacker with local access and user interaction to cause high integrity and availability impact, and some confidentiality loss. This could result in system instability, data corruption, or unauthorized modification of data within the affected Graphite installation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should restrict local access and limit user interaction with the vulnerable Graphite versions. Monitor vendor channels for updates and apply patches once released.
CVE-2026-50593: CWE-191 Integer Underflow (Wrap or Wraparound) in Graphite project Graphite
Description
Graphite versions prior to 1.3.15 contain an integer underflow vulnerability that leads to an out-of-bounds write. This occurs because the 'slotat' function does not properly validate that an offset is within the allowed slot-map range. The vulnerability has a high severity with a CVSS score of 7.3.
CVSS v3.1
Score 7.3high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-50593 is an integer underflow vulnerability in the Graphite project affecting versions before 1.3.15. The issue arises from the 'slotat' function failing to ensure that an offset is within the valid slot-map range, which can cause an integer underflow and result in an out-of-bounds write. This can impact confidentiality, integrity, and availability as indicated by the CVSS vector (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H). No official patch or remediation level is currently documented.
Potential Impact
Successful exploitation can lead to an out-of-bounds write, potentially allowing an attacker with local access and user interaction to cause high integrity and availability impact, and some confidentiality loss. This could result in system instability, data corruption, or unauthorized modification of data within the affected Graphite installation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should restrict local access and limit user interaction with the vulnerable Graphite versions. Monitor vendor channels for updates and apply patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-06-05T02:14:32.977Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a22438ee29bf47b50241063
Added to database: 06/05/2026, 03:33:34 UTC
Last enriched: 06/12/2026, 10:30:46 UTC
Last updated: 07/25/2026, 20:52:05 UTC
Views: 109
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.