A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initiate the attack remotely. The exploit has been published and may be used. The maintainer was notified on Aug 2025 and a disclosure deadline was set for 90 days. The maintainer acknowledged but postponed indefinitely citing time concerns. No patch is currently available and the disclosure deadline has expired.
Metrics
Affected Vendors & Products
References
History
Sun, 07 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initiate the attack remotely. The exploit has been published and may be used. The maintainer was notified on Aug 2025 and a disclosure deadline was set for 90 days. The maintainer acknowledged but postponed indefinitely citing time concerns. No patch is currently available and the disclosure deadline has expired. | |
| Title | Boost Serialization improper validation of specified type of input | |
| First Time appeared |
Boost
Boost serialization |
|
| Weaknesses | CWE-1287 CWE-20 |
|
| CPEs | cpe:2.3:a:boost:serialization:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Boost
Boost serialization |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-07T19:30:10.324Z
Reserved: 2026-06-07T07:25:46.611Z
Link: CVE-2026-11460
No data.
No data.
No data.
OpenCVE Enrichment
No data.