CVE-2026-24874

9.1

themrdemonized · xray-monolith

A type confusion vulnerability in themrdemonized xray-monolith allows unauthenticated remote attackers to potentially access or manipulate system resources.

Executive summary

A critical type confusion vulnerability in xray-monolith (before 2025.12.30) poses a high risk of unauthorized data access or integrity compromise to unauthenticated remote attackers.

Vulnerability

This is a Type Confusion vulnerability (CWE-843) occurring within the application. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that the vulnerability is exploitable by an unauthenticated remote attacker without requiring user interaction.

Business impact

The vulnerability carries a CVSS score of 9.1, reflecting its high potential for severe impact. Successful exploitation could lead to unauthorized access to sensitive data or modification of critical system information, potentially resulting in significant operational disruption and data breach consequences.

Remediation

Immediate Action: Upgrade to version 2025.12.30 or later to apply the necessary security fixes provided by the vendor.

Proactive Monitoring: Monitor system logs for unusual traffic patterns or errors that might indicate an attempt to exploit memory-related vulnerabilities.

Compensating Controls: Implement a Web Application Firewall (WAF) with updated rulesets to identify and block malformed requests that may attempt to trigger type confusion.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical CVSS severity and the low complexity required for exploitation, organizations using xray-monolith should prioritize patching immediately. Ensure that the updated version is deployed across all affected environments to mitigate the risk of unauthorized access.