CVE-2026-2259

Source
https://cve.org/CVERecord?id=CVE-2026-2259
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2259.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-2259
Published
2026-02-10T02:32:08.234Z
Modified
2026-08-12T15:31:39.738202Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
aardappel lobster Parsing parser.h ParseStatements memory corruption
Details

A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The identifier of the patch is 2f45fe860d00990e79e13250251c1dde633f1f89. Applying a patch is the recommended action to fix this issue.

Database specific
{
    "cwe_ids": [
        "CWE-119"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2259.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/aardappel/lobster

Affected ranges

Type
GIT
Repo
https://github.com/aardappel/lobster
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:strlen:lobster:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2025.4"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

2025.*
2025.0
2025.1
2025.2
2025.3
2025.4
Other
before_namespace_change
last_coroutine
last_dynamically_typed
last_frame_log
last_interpreter
last_wasm_generator_enabled
lastruntimerefc
v2021.*
v2021.0
v2021.1
v2021.3
v2023.*
v2023.10
v2023.12
v2023.13
v2023.2
v2023.4
v2023.5
v2023.6
v2023.7
v2023.8
v2023.9
v2024.*
v2024.0
v2025.*
v2025.0
v2025.1
v2025.2
v2025.3
v2025.4

Database specific

vanir_signatures_modified
"2026-08-12T15:31:39Z"
vanir_signatures
[
    {
        "id": "CVE-2026-2259-e795595a",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "14431847067098788917002389626945123796",
                "198016880518592490858131099026057322917",
                "299841096168451569541472544696957966366",
                "267498294270574172788541796230356870511",
                "70106359949407829395778539218672129610",
                "9168717164632508204389848901840988727",
                "198852430302128499859780812772647066979",
                "16988111020498090564702997369260342090"
            ]
        },
        "source": "https://github.com/aardappel/lobster/commit/2f45fe860d00990e79e13250251c1dde633f1f89",
        "target": {
            "file": "dev/src/lobster/parser.h"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2259.json"