CVE-2026-2259

Source
https://cve.org/CVERecord?id=CVE-2026-2259
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2259.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-2259
Published
2026-02-10T04:16:05.433Z
Modified
2026-03-02T08:04:38.012524Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The identifier of the patch is 2f45fe860d00990e79e13250251c1dde633f1f89. Applying a patch is the recommended action to fix this issue.

References

Affected packages

Git / github.com/aardappel/lobster

Affected ranges

Type
GIT
Repo
https://github.com/aardappel/lobster
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other
before_namespace_change
last_coroutine
last_dynamically_typed
last_frame_log
last_interpreter
last_wasm_generator_enabled
lastruntimerefc
v2021.*
v2021.0
v2021.1
v2021.3
v2023.*
v2023.10
v2023.12
v2023.13
v2023.2
v2023.4
v2023.5
v2023.6
v2023.7
v2023.8
v2023.9
v2024.*
v2024.0
v2025.*
v2025.0
v2025.1
v2025.2
v2025.3
v2025.4

Database specific

vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-2259-e795595a",
        "target": {
            "file": "dev/src/lobster/parser.h"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "14431847067098788917002389626945123796",
                "198016880518592490858131099026057322917",
                "299841096168451569541472544696957966366",
                "267498294270574172788541796230356870511",
                "70106359949407829395778539218672129610",
                "9168717164632508204389848901840988727",
                "198852430302128499859780812772647066979",
                "16988111020498090564702997369260342090"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/aardappel/lobster/commit/2f45fe860d00990e79e13250251c1dde633f1f89"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2259.json"