CVE-2026-49328: Custom Improper Magic Byte Evaluation

Extracting a fixed, generously large layout of magic bytes and looking it up within a strict key/value mapping can cause parsing mismatch if expected formats use much shorter signatures, potentially short-circuiting file validation.

Provally CuratedPublic repositoryLowMedium confidenceVerifiedApache-2.0Java
greprules fetch cve-2026-49328-custom-improper-magic-byte-evaluation --engine opengrep

Description

Extracting a fixed, generously large layout of magic bytes and looking it up within a strict key/value mapping can cause parsing mismatch if expected formats use much shorter signatures, potentially short-circuiting file validation.