{"id":"CVE-2021-41193","aliases":["GHSA-2j6v-xpf3-xvrv"],"url":"https://o3.security/vulnerability/CVE-2021-41193","summary":"Use of Externally-Controlled Format String in wire-avs","details":"wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs 7.1.12. There are currently no known workarounds.","published":"2022-03-01T19:15:08.403Z","modified":"2026-07-09T15:01:35.586492Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.02466,"percentile":0.83147,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.wire:avs","fixedVersion":"7.1.12"}],"fix":{"url":"https://github.com/wireapp/wire-avs/commit/40d373ede795443ae6f2f756e9fb1f4f4ae90bbe","label":"wireapp/wire-avs@40d373e"},"references":[{"type":"FIX","url":"https://github.com/wireapp/wire-avs/commit/40d373ede795443ae6f2f756e9fb1f4f4ae90bbe"},{"type":"FIX","url":"https://github.com/wireapp/wire-avs/security/advisories/GHSA-2j6v-xpf3-xvrv"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T15:01:35.586492Z"}}