CVE-2026-0049: exploitation status and patch state
CVE-2026-0049 · CVSS 6.2 MEDIUM · EPSS <1%
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Is CVE-2026-0049 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.