CVE-2026-100895

Source
https://cve.org/CVERecord?id=CVE-2026-100895
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100895.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100895
Published
2026-09-28T01:15:11Z
Modified
2026-09-30T03:30:24Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereference
Details

A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-404",
        "CWE-476"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100895.json"
}
References

Affected packages

Git / github.com/trusteddomainproject/openarc

Affected ranges

Type
GIT
Repo
https://github.com/trusteddomainproject/openarc
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.0.0.Beta1"
        },
        {
            "last_affected":  "1.0.0.Beta1"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

1.*
1.0.0.Beta1
v1.*
v1.0.0.Beta1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100895.json"