PT-2026-2027 · Unknown+1 · Quickjs-Ng+1
Mcsky23
+1
·
Published
2026-01-10
·
Updated
2026-01-10
·
CVE-2026-0821
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
quickjs-ng versions up to 0.11.0
Description
A flaw exists in quickjs-ng up to version 0.11.0 due to a heap-based buffer overflow in the
js typed array constructor function within the quickjs.c file. This issue can be triggered remotely through a manipulation. The exploit for this issue has been publicly disclosed.Recommendations
Apply the patch c5d80831e51e48a83eab16ea867be87f091783c5 to remediate this issue.
Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Quickjs-Ng