Intel

AIKIDO-2026-10714

github.com/bytedance/sonic is vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer

Improper Restriction of Operations within the Bounds of a Memory Buffer Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 4, 2026

88

High Risk

This Affects:

GOgithub.com/bytedance/sonic
0.0.1 - 1.15.0
Fixed in 1.15.1
Are you affected? Scan for Free

TL;DR

Prior to version 1.15.1, the decoder could corrupt memory when decoding into a prefilled interface value. This vulnerability could lead to memory corruption and undefined behavior if attackers supplied specially crafted input.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/bytedance/sonic is vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer in versions 0.0.1 - 1.15.0.

How to fix this

Upgrade the github.com/bytedance/sonic library to the patch version.