PT-2026-7120 · Unknown · Janet-Lang

Oneafter

·

Published

2026-02-09

·

Updated

2026-02-25

·

CVE-2026-2240

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions janet-lang janet versions prior to 1.40.1
Description A flaw exists in the janet-lang programming language compiler, specifically within the janetc pop funcdef function located in the src/core/compile.c file. This issue allows for an out-of-bounds read when triggered locally. The exploit for this issue has been publicly disclosed.
Recommendations Apply the patch with identifier 4dd08a4cdef5b1c42d9a2c19fc24412e97ef51d5 to remediate this issue.

Exploit

Fix

Buffer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-2240

Affected Products

Janet-Lang