CVE-2026-3979
Severity CVSS v4.0:
LOW
Type:
CWE-119
Buffer Errors
Publication date:
12/03/2026
Last modified:
29/04/2026
Description
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying a patch is the recommended action to fix this issue.
Impact
Base Score 4.0
1.90
Severity 4.0
LOW
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/quickjs-ng/quickjs/
- https://github.com/quickjs-ng/quickjs/commit/daab4ad4bae4ef071ed0294618d6244e92def4cd
- https://github.com/quickjs-ng/quickjs/issues/1368
- https://github.com/quickjs-ng/quickjs/issues/1368#issue-4004680962
- https://github.com/quickjs-ng/quickjs/pull/1370
- https://vuldb.com/?ctiid.350414
- https://vuldb.com/?id.350414
- https://vuldb.com/?submit.769600



