CVE-2025-46688
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/04/2025
Last modified:
30/05/2025
Description
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Impact
Base Score 3.x
5.60
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:quickjs-ng:quickjs:*:*:*:*:*:*:*:* | 0.9.0 (including) | |
| cpe:2.3:a:quickjs_project:quickjs:*:*:*:*:*:*:*:* | 2025-04-26 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://bellard.org/quickjs/Changelog
- https://github.com/bellard/quickjs/commit/1eb05e44fad89daafa8ee3eb74b8520b4a37ec9a
- https://github.com/bellard/quickjs/issues/399
- https://github.com/quickjs-ng/quickjs/commit/28fa43d3ddff2c1ba91b6e3a788b2d7ba82d1465
- https://github.com/quickjs-ng/quickjs/issues/1018
- https://github.com/quickjs-ng/quickjs/pull/1020
- https://github.com/quickjs-ng/quickjs/issues/1018



