PT-2026-3428 · Quickjs+1 · Quickjs+1

Mcsky23

·

Published

2026-01-19

·

Updated

2026-01-19

·

CVE-2026-1145

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions quickjs-ng versions up to 0.11.0
Description A flaw exists in quickjs-ng quickjs due to a heap-based buffer overflow in the js typed array constructor ta function within the quickjs.c file. This manipulation allows for remote exploitation. An exploit for this issue has been published.
Recommendations Install patch 53aebe66170d545bb6265906fe4324e4477de8b4 to address this issue.

Exploit

Fix

Buffer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-1145

Affected Products

Quickjs
Quickjs-Ng