<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>bitwize music — Security Advisories</title><link>https://www.bitwizemusic.com/security/advisories/</link><description>Vulnerability disclosures by bitwize under the BVE identifier scheme.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 22 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.bitwizemusic.com/security/advisories/index.xml" rel="self" type="application/rss+xml"/><item><title>BVE-2026-0006 — Reserved</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0006/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0006/</guid><category>code-execution</category><category>local</category><description><![CDATA[<p>A local code execution vulnerability discovered on 2026-04-19. It has been reported to the vendor, with a CVE requested on 2026-04-22. Full details will be published here once disclosure is complete.</p>
        <p><strong>Status:</strong> Reserved. <strong>Severity:</strong> High. 
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0006/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0005 — Reserved</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0005/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0005/</guid><category>rce</category><category>unauthenticated</category><description><![CDATA[<p>A critical unauthenticated remote code execution vulnerability discovered on 2026-04-19 and reported to the Zero Day Initiative (ZDI) the same day. Full details will be published here once disclosure is complete.</p>
        <p><strong>Status:</strong> Reserved. <strong>Severity:</strong> Critical. 
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0005/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0004 — Reserved</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0004/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0004/</guid><category>rce</category><category>unauthenticated</category><description><![CDATA[<p>A critical unauthenticated remote code execution vulnerability discovered on 2026-04-19 and reported to the Zero Day Initiative (ZDI) the same day. Full details will be published here once disclosure is complete.</p>
        <p><strong>Status:</strong> Reserved. <strong>Severity:</strong> Critical. 
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0004/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0002 — ok_json: heap buffer overread in UTF-8 validation</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0002/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0002/</guid><category>heap-buffer-overread</category><category>json-parser</category><category>memory-safety</category><category>utf-8</category><description><![CDATA[<p>A heap buffer overread in ok_json&#39;s UTF-8 validator. A multi-byte UTF-8 lead byte at the end of input causes the validator to read continuation bytes past the end of the caller-supplied buffer. Fixed upstream on 2026-04-14.</p>
        <p><strong>Status:</strong> Fixed. <strong>Severity:</strong> High. <strong>Vendor:</strong> ionux. <strong>Product:</strong> ok_json.
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0002/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0003 — ok_json: heap buffer overread in true/false/null keyword matching</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0003/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0003/</guid><category>heap-buffer-overread</category><category>json-parser</category><category>memory-safety</category><description><![CDATA[<p>A heap buffer overread in ok_json&#39;s keyword matcher. Input shorter than the expected keyword (`true`, `false`, `null`) causes `okj_match` to read past the end of the caller-supplied buffer. Fixed upstream on 2026-04-14.</p>
        <p><strong>Status:</strong> Fixed. <strong>Severity:</strong> High. <strong>Vendor:</strong> ionux. <strong>Product:</strong> ok_json.
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0003/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0001 — ok_json: heap buffer overread in \uXXXX escape parsing</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0001/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0001/</guid><category>heap-buffer-overread</category><category>json-parser</category><category>memory-safety</category><description><![CDATA[<p>A heap buffer overread in ok_json&#39;s `\uXXXX` escape parser. A truncated `\u` escape at the end of input causes the parser to read past the end of the caller-supplied buffer while consuming hex digits. Fixed upstream on 2026-04-14.</p>
        <p><strong>Status:</strong> Fixed. <strong>Severity:</strong> High. <strong>Vendor:</strong> ionux. <strong>Product:</strong> ok_json.
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0001/">View advisory</a></p>
      ]]></description></item></channel></rss>