CVE-2026-0821
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-119
Restricción de operaciones inapropiada dentro de los límites del búfer de la memoria
Fecha de publicación:
10/01/2026
Última modificación:
10/01/2026
Descripción
*** Pendiente de traducción *** A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called c5d80831e51e48a83eab16ea867be87f091783c5. A patch should be applied to remediate this issue.
Impacto
Puntuación base 4.0
6.90
Gravedad 4.0
MEDIA
Puntuación base 3.x
7.30
Gravedad 3.x
ALTA
Puntuación base 2.0
7.50
Gravedad 2.0
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/quickjs-ng/quickjs/commit/c5d80831e51e48a83eab16ea867be87f091783c5
- https://github.com/quickjs-ng/quickjs/issues/1296
- https://github.com/quickjs-ng/quickjs/issues/1296#issue-3780003395
- https://github.com/quickjs-ng/quickjs/pull/1299
- https://vuldb.com/?ctiid_340355=
- https://vuldb.com/?id_340355=
- https://vuldb.com/?submit_731780=



