PT-2026-22510 · Squirrel · Squirrel

Oneafter

·

Publicado

2026-01-01

·

Atualizado

2026-03-05

·

CVE-2026-3388

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Squirrel versions prior to 3.3
Description A flaw exists in the Squirrel compiler, specifically within the SQCompiler::Factor and SQCompiler::UnaryOP functions located in the squirrel/sqcompiler.cpp file. This issue allows for uncontrolled recursion through manipulation, potentially leading to a denial-of-service condition. The exploit has been publicly released. The issue was reported to the project developers, but no response has been received.
Recommendations Versions prior to 3.3 should be updated. As a temporary workaround, consider restricting or disabling the use of the SQCompiler::Factor and SQCompiler::UnaryOP functions until a patch is available.

Exploit

Correção

Uncontrolled Recursion

Improper Resource Release

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3388

Produtos afetados

Squirrel