CVE-2026-24738 is a resource exhaustion vulnerability in the gmrtd Go library, affecting versions prior to 0.17.2. The vulnerability allows attackers to cause unconstrained memory and CPU consumption by sending excessively large TLV lengths (up to 4GB) when reading Machine Readable Travel Documents (MRTDs). This can lead to extreme slowdowns or memory exhaustion on devices, particularly phones, interacting with malicious NFCs. Rated with a CVSS score of 6.5 (Medium), this vulnerability has an adjacent attack vector (AV:A) and low attack complexity (AC:L), requiring no privileges (PR:N) or user interaction (UI:N). The primary impact is high availability (A:H) due to resource exhaustion, with no impact on confidentiality or integrity. There is currently no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.17.2CPE matchmatch criteria | cpe:2.3:a:gmrtd:gmrtd:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.