CVE-2026-0049 is a resource exhaustion vulnerability in the onHeaderDecoded function of LocalImageResolver.java that enables persistent denial of service attacks through uncontrolled resource consumption. The vulnerability allows an attacker to exhaust system resources and render affected services unavailable. This vulnerability affects local systems and requires no additional privileges or user interaction for exploitation. The vulnerability carries a CVSS score of 6.2 (Medium severity) with a local attack vector and low complexity, indicating it is relatively straightforward to exploit from the local system. While the attack does not compromise confidentiality or integrity, it has a high impact on availability, potentially causing complete service disruption. The associated FAUCET risk score of 44.0 reflects moderate concern within the threat landscape. Currently, there is no evidence of active exploitation in the wild, as the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list and remains inactive on relevant threat tracking lists. The extremely low EPSS score of 0.00007 suggests minimal real-world exploitation probability at this time, indicating this is not an immediate threat despite its medium severity rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.0CPE matchmatch criteria | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* | ||
16.0CPE matchmatch criteria | cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:* | ||
16.0CPE matchmatch criteria | cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:* | ||
16.0CPE matchmatch criteria | cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.