Vulnerabilities we found.

Security flaws discovered by Sigreturn Labs researchers, disclosed responsibly to the affected vendors, or, when the target is malware, turned into recovery tooling for its victims. Some carry a CVE, some have one pending attribution, and some are tracked without one. Each is credited to the researcher who found it.

11 advisories, all credited to Adam Taguirov

Goodware6

Flaws in legitimate software, disclosed responsibly to the vendor.

SeverityVulnerabilityClassStatusDate
CriticalHeap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch)SAILHeap buffer overflowCWE-122CVE-2026-546267 Jun 2026
CriticalHeap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth)SAILHeap buffer overflowCWE-122CVE-2026-546277 Jun 2026
MediumDouble-free in 3DSOLID/BODY/REGION encodingGNU LibreDWGDouble freeCWE-415CVE pending31 May 2026
MediumHeap out-of-bounds read in bit_TV_to_utf8GNU LibreDWGOut-of-bounds readCWE-125CVE pending31 May 2026
High Under embargoPending coordinated disclosureEmbargoed
Medium Under embargoPending coordinated disclosureEmbargoed

Malware5

Weaknesses in malware, turned into recovery tooling for its victims.

SeverityVulnerabilityClassStatusDate
CriticalRecoverable file-encryption keys in Rhysida ransomware (timestamp-seeded PRNG)Rhysida ransomwarePredictable PRNG seedCWE-337No CVE15 May 2023
Critical Under embargoPending coordinated disclosureRecoverable encryptionEmbargoed
Critical Under embargoPending coordinated disclosureRecoverable encryptionEmbargoed
Critical Under embargoPending coordinated disclosureRecoverable encryptionEmbargoed
Critical Under embargoPending coordinated disclosureRecoverable encryptionEmbargoed