PT-2026-20354 · Unknown · Universal-Ctags
Oneafter
·
Published
2026-02-18
·
Updated
2026-02-18
·
CVE-2026-2641
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
universal-ctags versions up to 6.2.1
Description
A flaw exists in the V Language Parser component of universal-ctags. Specifically, the
parseExpression/parseExprList functions within the parsers/v.c file are susceptible to uncontrolled recursion. This can be triggered through manipulation and is exploitable on a local host. The exploit code has been publicly released. The project maintainers were notified of the issue but have not yet responded.Recommendations
Versions prior to 6.2.1 are affected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Uncontrolled Recursion
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Universal-Ctags