CVE-2026-24794: Cardboardpowered Cardboard

Critical severity, CVSS 9.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in CardboardPowered cardboard (src/main/java/org/cardboardpowered/impl/world modules). This vulnerability is associated with program files WorldImpl.Java. This issue affects cardboard: before 1.21.4.

Affected products

Published 2026-01-27. Last modified 2026-06-17.