PT-2026-30709 · Unknown · Openfpgaloader

Sebasteuo

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-35170

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions openFPGALoader versions 1.1.1 and earlier
Description openFPGALoader is a utility for programming FPGAs. A heap-buffer-overflow read vulnerability exists in the BitParser::parseHeader() function when parsing a crafted .bit file, allowing out-of-bounds heap memory access. No FPGA hardware is required to trigger this issue.
Recommendations Update to a version later than 1.1.1.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-35170

Affected Products

Openfpgaloader