CVE-2026-10267
3.3 LOWA security flaw has been discovered in janet-lang janet up to 1.41.0
Published: 2026-06-01 · Last updated: 2026-06-01
Severity and scoring
- CVSS
- 3.3 LOW
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- CWE
- CWE-119, CWE-125
Description
A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/core/debug.c. Performing a manipulation results in out-of-bounds read. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named ed17dd2c5913a23fb1107251e44a9410a3c30cf5.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-10267
- [Other]https://github.com/biniamf/pocs/tree/main/janet-debug-janet-doframe-env-data-oobread
- [Other]https://github.com/janet-lang/janet/
- [Other]https://github.com/janet-lang/janet/commit/ed17dd2c5913a23fb1107251e44a9410a3c30cf5
- [Other]https://github.com/janet-lang/janet/issues/1743
- [Other]https://github.com/janet-lang/janet/issues/1743#issuecomment-4322129448
- [Other]https://vuldb.com/cve/CVE-2026-10267
- [Other]https://vuldb.com/submit/825072
- [Other]https://vuldb.com/vuln/367546
- [Other]https://vuldb.com/vuln/367546/cti
Related CVEs
Same CWE
- CVE-2026-47166 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.7 MEDIUM)
- CVE-2026-45624 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.1 MEDIUM)
- CVE-2026-45359 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.7 MEDIUM)
- CVE-2026-45358 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.3 MEDIUM)
- CVE-2026-42326 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.1 MEDIUM)