PT-2026-21378 · Unknown · Janet-Lang

Oneafter

·

Published

2026-02-21

·

Updated

2026-02-22

·

CVE-2026-2869

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions janet-lang versions prior to 1.41.0
Description A flaw exists in the janet-lang software, specifically within the janetc varset function located in the src/core/specials.c file, part of the handleattr Handler component. This issue can lead to an out-of-bounds read. The vulnerability is locally exploitable, and an exploit is publicly available.
Recommendations Upgrade to version 1.41.0 to address this issue.

Exploit

Fix

Buffer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-2869

Affected Products

Janet-Lang