CVE-2026-48689: Cpp Capacity Off By One

An improper bounds check was found where a required capacity upper limit is incorrectly increased by one (`> size + 1`). This off-by-one limit validation allows exactly one byte to be written or read out of bounds. Ensure limits bounds rely strictly on exact sizes, checking `offset + length > size`.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C++
greprules fetch cve-2026-48689-cpp-capacity-off-by-one --engine opengrep

Description

An improper bounds check was found where a required capacity upper limit is incorrectly increased by one (`> size + 1`). This off-by-one limit validation allows exactly one byte to be written or read out of bounds. Ensure limits bounds rely strictly on exact sizes, checking `offset + length > size`.