CVE-2026-107611
Out-of-bounds read in TightVNC Viewer ZRLE palette decoding
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th
An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer.
| CWE | CWE-125 |
| Vendor | glavsoft |
| Product | tightvnc |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for glavsoft tightvnc
Be the first to know when new high vulnerabilities affecting glavsoft tightvnc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
GlavSoft / TightVNC
0 < 2.8.88
References
Credits
Arjun Basnet from Securin