PT-2026-22510 · Squirrel · Squirrel

Oneafter

·

Published

2026-01-01

·

Updated

2026-03-05

·

CVE-2026-3388

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Squirrel versions prior to 3.3
Description A flaw exists in the Squirrel compiler, specifically within the SQCompiler::Factor and SQCompiler::UnaryOP functions located in the squirrel/sqcompiler.cpp file. This issue allows for uncontrolled recursion through manipulation, potentially leading to a denial-of-service condition. The exploit has been publicly released. The issue was reported to the project developers, but no response has been received.
Recommendations Versions prior to 3.3 should be updated. As a temporary workaround, consider restricting or disabling the use of the SQCompiler::Factor and SQCompiler::UnaryOP functions until a patch is available.

Exploit

Fix

Uncontrolled Recursion

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3388

Affected Products

Squirrel