CVE-2026-68911EPSS p20.8%
CVE-2026-68911CVE-2026-68911
Description
Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11.
Scoring
| EPSS | 0.30% probability of exploitation · percentile 20.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |