A vulnerability labeled as problematic has been found in ndsev zserio up to 2.18.0. This vulnerability affects the function readBytes/readString/setBitPosition in the library BitStreamReader.h. Such manipulation leads to integer overflow.

This vulnerability is documented as CVE-2026-33666. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.