CVE-2026-90716: marcobambini Gravity Number gravity_parser.c parse_number_expression out-of-bounds
A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parsenumberexpression of the file src/compiler/gravityparser.c of the component Number Parser. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 0.9.8 will fix this issue. The patch is named 1b9bbf3ad5749e2a3434e6ad073c6e93c24207b6. It is recommended to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
marcobambini Gravityto a version that resolves this vulnerability.Fixed in 0.9.8Patch 1b9bbf3ad5749e2a3434e6ad073c6e93c24207b6
Event History
Frequently Asked Questions
Which deployments are affected?
Gravity versions up to and including 0.9.7 are affected. Version 0.9.8 fixes the issue.
What access does an attacker need to exploit this?
The issue can be triggered remotely, but the severity vector indicates the attacker needs low-level privileges and user interaction. Exploitation involves manipulating input handled by the Number Parser.
Is exploit code available?
Yes. The available information states that a public exploit exists and may be used.
What should teams do if they are affected?
Upgrade Gravity to version 0.9.8. The identified fix is patch 1b9bbf3ad5749e2a3434e6ad073c6e93c24207b6.