CVE-2026-4746: Timeplus-Io Proton

Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules). This vulnerability is associated with program files inflate.C. This issue affects proton: before 1.6.16.

Affected products

Published 2026-03-24. Last modified 2026-06-17.