CVE-2026-68911: Nicotine+: Decompression of peer messages can exhaust available memory
Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nicotine+to a version that resolves this vulnerability.Fixed in 3.3.11
Event History
Frequently Asked Questions
Who can exploit this issue?
A modified remote Soulseek client can exploit the issue by sending a crafted zlib-compressed peer message to a vulnerable Nicotine+ client.
Which installations are affected?
Nicotine+ versions prior to 3.3.11 are affected. The issue is patched in version 3.3.11.
What is the impact of successful exploitation?
Processing a decompression bomb can exhaust the recipient operating system's available memory.