CVE-2026-68911: Nicotine-Plus

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11.

Affected products

Published 2026-09-29. Last modified 2026-09-30.