CVE-2026-86716

Source
https://cve.org/CVERecord?id=CVE-2026-86716
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86716.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86716
Published
2026-09-08T18:45:05Z
Modified
2026-09-10T03:48:30Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow
Details

A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86716.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.0"
                },
                {
                    "last_affected": "1.0"
                },
                {
                    "introduced": "1.1"
                },
                {
                    "last_affected": "1.1"
                },
                {
                    "introduced": "1.2"
                },
                {
                    "last_affected": "1.2"
                },
                {
                    "introduced": "1.3"
                },
                {
                    "last_affected": "1.3"
                },
                {
                    "introduced": "1.4"
                },
                {
                    "last_affected": "1.4"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/cesanta/mjs

Affected ranges

Type
GIT
Repo
https://github.com/cesanta/mjs
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.5"
        },
        {
            "last_affected": "1.5"
        },
        {
            "introduced": "1.6"
        },
        {
            "last_affected": "1.6"
        },
        {
            "introduced": "1.7"
        },
        {
            "last_affected": "1.7"
        },
        {
            "introduced": "1.8"
        },
        {
            "last_affected": "1.8"
        },
        {
            "introduced": "1.9"
        },
        {
            "last_affected": "1.9"
        },
        {
            "introduced": "1.10"
        },
        {
            "last_affected": "1.10"
        },
        {
            "introduced": "1.11"
        },
        {
            "last_affected": "1.11"
        },
        {
            "introduced": "1.12"
        },
        {
            "last_affected": "1.12"
        },
        {
            "introduced": "1.13"
        },
        {
            "last_affected": "1.13"
        },
        {
            "introduced": "1.14"
        },
        {
            "last_affected": "1.14"
        },
        {
            "introduced": "1.15"
        },
        {
            "last_affected": "1.15"
        },
        {
            "introduced": "1.16"
        },
        {
            "last_affected": "1.16"
        },
        {
            "introduced": "1.17"
        },
        {
            "last_affected": "1.17"
        },
        {
            "introduced": "1.18"
        },
        {
            "last_affected": "1.18"
        },
        {
            "introduced": "1.19"
        },
        {
            "last_affected": "1.19"
        },
        {
            "introduced": "1.20"
        },
        {
            "last_affected": "1.20"
        },
        {
            "introduced": "1.21"
        },
        {
            "last_affected": "1.21"
        },
        {
            "introduced": "1.22"
        },
        {
            "last_affected": "1.22"
        },
        {
            "introduced": "1.23"
        },
        {
            "last_affected": "1.23"
        },
        {
            "introduced": "1.24"
        },
        {
            "last_affected": "1.24"
        },
        {
            "introduced": "1.25"
        },
        {
            "last_affected": "1.25"
        },
        {
            "introduced": "1.26"
        },
        {
            "last_affected": "1.26"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.10
1.11
1.12
1.13
1.14
1.15
1.16
1.17
1.18
1.19
1.19.1
1.19.2
1.19.3
1.19.4
1.19.5
1.19.6
1.20
1.20.1
1.21
1.22
1.22.1
1.23
1.24
1.25
1.26
1.5
1.6
1.7
1.8
1.9
Other
ddd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86716.json"