A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mpimportall of the file py/runtime.c. This manipulation causes memory corruption. The attack needs to be launched locally. The exploit has been published and may be used. Patch name: 570744d06c5ba9dba59b4c3f432ca4f0abd396b6. It is suggested to install a patch to address this issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1998.json",
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119"
]
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "1.0"
},
{
"last_affected": "1.0"
},
{
"introduced": "1.1"
},
{
"last_affected": "1.1"
},
{
"introduced": "1.2"
},
{
"last_affected": "1.2"
},
{
"introduced": "1.3"
},
{
"last_affected": "1.3"
},
{
"introduced": "1.4"
},
{
"last_affected": "1.4"
},
{
"introduced": "1.5"
},
{
"last_affected": "1.5"
},
{
"introduced": "1.6"
},
{
"last_affected": "1.6"
},
{
"introduced": "1.7"
},
{
"last_affected": "1.7"
},
{
"introduced": "1.8"
},
{
"last_affected": "1.8"
},
{
"introduced": "1.9"
},
{
"last_affected": "1.9"
},
{
"introduced": "1.10"
},
{
"last_affected": "1.10"
},
{
"introduced": "1.11"
},
{
"last_affected": "1.11"
},
{
"introduced": "1.12"
},
{
"last_affected": "1.12"
},
{
"introduced": "1.13"
},
{
"last_affected": "1.13"
},
{
"introduced": "1.14"
},
{
"last_affected": "1.14"
},
{
"introduced": "1.15"
},
{
"last_affected": "1.15"
},
{
"introduced": "1.16"
},
{
"last_affected": "1.16"
},
{
"introduced": "1.17"
},
{
"last_affected": "1.17"
},
{
"introduced": "1.18"
},
{
"last_affected": "1.18"
},
{
"introduced": "1.19"
},
{
"last_affected": "1.19"
},
{
"introduced": "1.20"
},
{
"last_affected": "1.20"
},
{
"introduced": "1.21"
},
{
"last_affected": "1.21"
},
{
"introduced": "1.22"
},
{
"last_affected": "1.22"
},
{
"introduced": "1.23"
},
{
"last_affected": "1.23"
},
{
"introduced": "1.24"
},
{
"last_affected": "1.24"
},
{
"introduced": "1.25"
},
{
"last_affected": "1.25"
},
{
"introduced": "1.26"
},
{
"last_affected": "1.26"
},
{
"introduced": "1.27.0"
},
{
"last_affected": "1.27.0"
}
]
}{
"cpe": "cpe:2.3:a:micropython:micropython:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.27.0"
}
]
}[
{
"signature_version": "v1",
"target": {
"file": "py/runtime.c"
},
"id": "CVE-2026-1998-147965e6",
"signature_type": "Line",
"source": "https://github.com/dpgeorge/micropython/commit/570744d06c5ba9dba59b4c3f432ca4f0abd396b6",
"digest": {
"line_hashes": [
"314669114127214206941191837999180491419",
"65734818014945278580344814902558745899",
"177405024897822420457758788821448099790",
"225847155566421643133302173562872750889",
"234598909790281932601038328374309982589",
"208159626100173812426223873924061901334",
"252008842346387433472178132375686175884",
"122239347192010381286493971473416362239",
"7032513319386658241733258425947740844",
"115679024746737187962769538353380490362",
"177450214957797854408443010396088667530",
"306912640794738765172445825369295727916",
"50376017993905550568569054536298303313",
"198035267221702008425483894545954342490",
"8226933511286249839914699664771962011",
"70388691493598608008399969543868429077"
],
"threshold": 0.9
},
"deprecated": false
},
{
"signature_version": "v1",
"target": {
"function": "mp_import_all",
"file": "py/runtime.c"
},
"id": "CVE-2026-1998-38e0d7a6",
"signature_type": "Function",
"source": "https://github.com/dpgeorge/micropython/commit/570744d06c5ba9dba59b4c3f432ca4f0abd396b6",
"digest": {
"function_hash": "30212119845419580799864898971790395502",
"length": 785.0
},
"deprecated": false
}
]
"2026-07-15T15:53:42Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1998.json"