editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in ecglob() that allows an attacker to crash any application using libeditorconfig by providing a specially crafted directory structure and .editorconfig file. This is an incomplete fix for CVE-2023-0341. The pcrestr buffer was protected in 0.12.6 but the adjacent lpattern[8194] stack buffer received no equivalent protection. On Ubuntu 24.04, FORTIFYSOURCE converts the overflow to SIGABRT (DoS). Version 0.12.11 contains an updated fix.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40489.json",
"cwe_ids": [
"CWE-121",
"CWE-787"
],
"cna_assigner": "GitHub_M"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.12.11"
}
]
}
[
{
"id": "CVE-2026-40489-3621160f",
"target": {
"function": "ec_glob",
"file": "src/lib/ec_glob.c"
},
"deprecated": false,
"digest": {
"function_hash": "113504869699976989321234718115873762603",
"length": 4558.0
},
"signature_version": "v1",
"source": "https://github.com/editorconfig/editorconfig-core-c/commit/5159be88ad50641d9843289adda791ba300421ff",
"signature_type": "Function"
},
{
"id": "CVE-2026-40489-3646f6de",
"target": {
"file": "src/lib/ec_glob.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"118771220304447511001250232753974064498",
"263396701957562860683093336295544499960",
"212725471622076258926958822295147843625",
"324446910542984109512982903483050839781",
"161666992118196387847668957860246513980"
]
},
"signature_version": "v1",
"source": "https://github.com/editorconfig/editorconfig-core-c/commit/5159be88ad50641d9843289adda791ba300421ff",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40489.json"
"2026-08-12T16:24:06Z"