Vulnerabilities we found.
Security flaws discovered by Sigreturn Labs researchers, disclosed responsibly to the affected vendors, or, when the target is malware, turned into recovery tooling for its victims. Some carry a CVE, some have one pending attribution, and some are tracked without one. Each is credited to the researcher who found it.
Goodware6
Flaws in legitimate software, disclosed responsibly to the vendor.
| Severity | Vulnerability | Class | Status | Date |
|---|---|---|---|---|
| Critical | Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch)SAIL | Heap buffer overflowCWE-122 | CVE-2026-54626 | 7 Jun 2026 |
| Critical | Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth)SAIL | Heap buffer overflowCWE-122 | CVE-2026-54627 | 7 Jun 2026 |
| Medium | Double-free in 3DSOLID/BODY/REGION encodingGNU LibreDWG | Double freeCWE-415 | CVE pending | 31 May 2026 |
| Medium | Heap out-of-bounds read in bit_TV_to_utf8GNU LibreDWG | Out-of-bounds readCWE-125 | CVE pending | 31 May 2026 |
| High | Pending coordinated disclosure | — | — | |
| Medium | Pending coordinated disclosure | — | — |
Malware5
Weaknesses in malware, turned into recovery tooling for its victims.
| Severity | Vulnerability | Class | Status | Date |
|---|---|---|---|---|
| Critical | Recoverable file-encryption keys in Rhysida ransomware (timestamp-seeded PRNG)Rhysida ransomware | Predictable PRNG seedCWE-337 | No CVE | 15 May 2023 |
| Critical | Pending coordinated disclosure | Recoverable encryption | — | |
| Critical | Pending coordinated disclosure | Recoverable encryption | — | |
| Critical | Pending coordinated disclosure | Recoverable encryption | — | |
| Critical | Pending coordinated disclosure | Recoverable encryption | — |