CVE-2026-22891
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
| CWE | CWE-122 |
| Vendor | the biosig project |
| Product | libbiosig |
| Published | Mar 3, 2026 |
| Last Updated | Mar 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for the biosig project libbiosig
Be the first to know when new critical vulnerabilities affecting the biosig project libbiosig are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
The Biosig Project / libbiosig
3.9.2 Master Branch (db9a9a63)
References
Credits
Discovered by Mark Bereza and Lilith >_> of Cisco Talos.