CVE-2026-50593: Graphite Project Graphite
High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
Affected products
- Graphite Project Graphite: before 1.3.15 (fixed in 1.3.15)
Published 2026-06-05. Last modified 2026-07-23.