Valentina Studio Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Valentina Studio version 9.0.4. This vulnerability allows local attackers to crash the application by sending an excessively long string in the Host field during server connection attempts. The crash can be triggered by pasting a 256-byte buffer of repeated characters into the Host parameter.

Impact

Exploitation of this vulnerability leads to a crash of the Valentina Studio application, causing a denial-of-service condition where the application becomes unresponsive or unavailable.

Reproduction

To reproduce this vulnerability, Valentina Studio 9.0.4 must be installed on a Windows operating system. After launching the application, navigate to 'File' > 'Connect to' and select 'Valentina Server'. In the 'Host' field, paste a 256-byte string of repeated characters. This action will cause the application to crash.

Added: Mar 30, 2026, 12:26 PM
Updated: Mar 30, 2026, 12:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.6
remediation
0.0
relevance
4.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.