CVE-2026-0821
Severity CVSS v4.0:
MEDIUM
Type:
CWE-119
Buffer Errors
Publication date:
10/01/2026
Last modified:
10/01/2026
Description
A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called c5d80831e51e48a83eab16ea867be87f091783c5. A patch should be applied to remediate this issue.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/quickjs-ng/quickjs/commit/c5d80831e51e48a83eab16ea867be87f091783c5
- https://github.com/quickjs-ng/quickjs/issues/1296
- https://github.com/quickjs-ng/quickjs/issues/1296#issue-3780003395
- https://github.com/quickjs-ng/quickjs/pull/1299
- https://vuldb.com/?ctiid_340355=
- https://vuldb.com/?id_340355=
- https://vuldb.com/?submit_731780=



