A security vulnerability has been detected in happyfish100 libfastcommon up to 1.0.84. Affected by this vulnerability is the function base64_decode of the file src/base64.c. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The identifier of the patch is 82f66af3e252e3e137dba0c3891570f085e79adf. Applying a patch is the recommended action to fix this issue.
{
"cwe_ids": [
"CWE-119",
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2016.json",
"cna_assigner": "VulDB",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"last_affected": "1.0.0"
},
{
"introduced": "1.0.1"
},
{
"last_affected": "1.0.1"
},
{
"introduced": "1.0.2"
},
{
"last_affected": "1.0.2"
},
{
"introduced": "1.0.3"
},
{
"last_affected": "1.0.3"
},
{
"introduced": "1.0.4"
},
{
"last_affected": "1.0.4"
},
{
"introduced": "1.0.5"
},
{
"last_affected": "1.0.5"
},
{
"introduced": "1.0.6"
},
{
"last_affected": "1.0.6"
},
{
"introduced": "1.0.8"
},
{
"last_affected": "1.0.8"
},
{
"introduced": "1.0.9"
},
{
"last_affected": "1.0.9"
},
{
"introduced": "1.0.10"
},
{
"last_affected": "1.0.10"
},
{
"introduced": "1.0.11"
},
{
"last_affected": "1.0.11"
},
{
"introduced": "1.0.12"
},
{
"last_affected": "1.0.12"
},
{
"introduced": "1.0.13"
},
{
"last_affected": "1.0.13"
},
{
"introduced": "1.0.14"
},
{
"last_affected": "1.0.14"
},
{
"introduced": "1.0.15"
},
{
"last_affected": "1.0.15"
},
{
"introduced": "1.0.16"
},
{
"last_affected": "1.0.16"
},
{
"introduced": "1.0.17"
},
{
"last_affected": "1.0.17"
},
{
"introduced": "1.0.18"
},
{
"last_affected": "1.0.18"
},
{
"introduced": "1.0.19"
},
{
"last_affected": "1.0.19"
},
{
"introduced": "1.0.20"
},
{
"last_affected": "1.0.20"
},
{
"introduced": "1.0.21"
},
{
"last_affected": "1.0.21"
},
{
"introduced": "1.0.22"
},
{
"last_affected": "1.0.22"
},
{
"introduced": "1.0.23"
},
{
"last_affected": "1.0.23"
},
{
"introduced": "1.0.24"
},
{
"last_affected": "1.0.24"
},
{
"introduced": "1.0.25"
},
{
"last_affected": "1.0.25"
},
{
"introduced": "1.0.26"
},
{
"last_affected": "1.0.26"
},
{
"introduced": "1.0.27"
},
{
"last_affected": "1.0.27"
},
{
"introduced": "1.0.28"
},
{
"last_affected": "1.0.28"
},
{
"introduced": "1.0.29"
},
{
"last_affected": "1.0.29"
},
{
"introduced": "1.0.30"
},
{
"last_affected": "1.0.30"
},
{
"introduced": "1.0.31"
},
{
"last_affected": "1.0.31"
},
{
"introduced": "1.0.32"
},
{
"last_affected": "1.0.32"
},
{
"introduced": "1.0.33"
},
{
"last_affected": "1.0.33"
},
{
"introduced": "1.0.34"
},
{
"last_affected": "1.0.34"
},
{
"introduced": "1.0.46"
},
{
"last_affected": "1.0.46"
}
]
}
]
}{
"cpe": "cpe:2.3:a:happyfish100:libfastcommon:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.0.84"
}
]
}"2026-07-21T23:45:10Z"
[
{
"signature_type": "Line",
"target": {
"file": "src/base64.c"
},
"deprecated": false,
"source": "https://github.com/happyfish100/libfastcommon/commit/82f66af3e252e3e137dba0c3891570f085e79adf",
"id": "CVE-2026-2016-25c24ad8",
"signature_version": "v1",
"digest": {
"line_hashes": [
"52792127485649528244036212812212428830",
"244564151359647250887928497871014904392",
"115955599080429114479581435839942501856",
"95170179270789726670019671868863176974",
"269103852097483132054304021673304595826",
"312328059861139713655210597605284791393",
"107991829929071671895191781611185296507",
"95687358357388333917042706157950859799",
"62932264688856123081586427316957088109",
"257219420171226631020597467776581962138",
"9183316775992320691999527670894350686",
"245661019840773830542518271704366194304",
"275403775594647015951378639441853682732",
"295045554048778348793230885893916908448"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "src/base64.c",
"function": "base64_decode"
},
"deprecated": false,
"source": "https://github.com/happyfish100/libfastcommon/commit/82f66af3e252e3e137dba0c3891570f085e79adf",
"id": "CVE-2026-2016-2b969434",
"signature_version": "v1",
"digest": {
"function_hash": "29041597499329794403442703817706983425",
"length": 1128.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2016.json"