CVE-2026-2259
Severity CVSS v4.0:
MEDIUM
Type:
CWE-119
Buffer Errors
Publication date:
10/02/2026
Last modified:
10/02/2026
Description
A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The identifier of the patch is 2f45fe860d00990e79e13250251c1dde633f1f89. Applying a patch is the recommended action to fix this issue.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
3.30
Severity 3.x
LOW
Base Score 2.0
1.70
Severity 2.0
LOW
References to Advisories, Solutions, and Tools
- https://github.com/aardappel/lobster/
- https://github.com/aardappel/lobster/commit/2f45fe860d00990e79e13250251c1dde633f1f89
- https://github.com/aardappel/lobster/issues/396
- https://github.com/aardappel/lobster/issues/396#issuecomment-3849019040
- https://github.com/oneafter/0204/blob/main/lob2/repro.lobster
- https://vuldb.com/?ctiid_345006=
- https://vuldb.com/?id_345006=
- https://vuldb.com/?submit_753168=



