QSearchQSearch

CVE-2026-25204

6.2 MEDIUM

Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via proces...

Published: 2026-04-13 · Last updated: 2026-06-02

Severity and scoring

CVSS
6.2 MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-502, CWE-843

Affected products

VendorProduct
samsungescargot

Description

Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via process abort. This issue affects escarogt prior to commit hash 97e8115ab1110bc502b4b5e4a0c689a71520d335

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-21033 Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local ... (7.1 HIGH)
  • CVE-2026-21032 Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local at... (7.1 HIGH)
  • CVE-2026-21031 Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity (7.8 HIGH)
  • CVE-2026-21030 Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions (7.8 HIGH)
  • CVE-2026-21029 Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to exec... (7.8 HIGH)

Same CWE

  • CVE-2026-48775 LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite) (6.8 MEDIUM)
  • CVE-2026-10748 An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating s...
  • CVE-2026-24228 NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data (7.8 HIGH)
  • CVE-2026-12299 JIT miscompilation in the DOM: Core & HTML component (5.4 MEDIUM)
  • CVE-2026-48853 Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unau...