PT-2026-47118 · Julia · Lua Jll

Published

2026-05-26

·

Updated

2026-05-26

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

Related Identifiers

JLSEC-2026-560

Affected Products

Lua Jll