PT-2026-7121 · Unknown · Janet-Lang

Oneafter

·

Published

2026-02-09

·

Updated

2026-02-25

·

CVE-2026-2241

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions janet-lang versions prior to 1.40.1
Description A flaw exists in the os strftime function within the src/core/os.c file of janet-lang. A manipulation of this function can lead to an out-of-bounds read. This issue requires local access to initiate the attack. The exploit is publicly available.
Recommendations Deploy the patch 0f285855f0e34f9183956be5f16e045f54626bff.

Exploit

Fix

Buffer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-2241

Affected Products

Janet-Lang