A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The identifier of the patch is 2f45fe860d00990e79e13250251c1dde633f1f89. Applying a patch is the recommended action to fix this issue.
[
{
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-2259-e795595a",
"target": {
"file": "dev/src/lobster/parser.h"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"14431847067098788917002389626945123796",
"198016880518592490858131099026057322917",
"299841096168451569541472544696957966366",
"267498294270574172788541796230356870511",
"70106359949407829395778539218672129610",
"9168717164632508204389848901840988727",
"198852430302128499859780812772647066979",
"16988111020498090564702997369260342090"
]
},
"signature_version": "v1",
"source": "https://github.com/aardappel/lobster/commit/2f45fe860d00990e79e13250251c1dde633f1f89"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2259.json"