CVE-2015-2311: Capnproto

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information from memory or execute arbitrary code via a crafted message.

Affected products

  • Capnproto Capnproto: up to and including 0.4.1.0; version 0.5.0.0 only; version 0.5.1.0 only

Published 2017-08-09. Last modified 2026-06-17.