An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with a digit, the integer digit-scan loop in lex() advances past the end of the input buffer and dereferences the out-of-bounds pointer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88344.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88344.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"298537850230673638645543380304689417130",
"58619515365624421221682272334695859297",
"62332699828865659022552210106442614114",
"229420838458747172363751533671299833382",
"338858592964460302613713744072750996067",
"136035547772697195397112517437463071076",
"170432091886214889760605210489107662067"
],
"threshold": 0.9
},
"id": "CVE-2026-88344-104a7b47",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/jimjag/flatcc/commit/c1dcc8ecd1a74b1e9e724ec7dc98828a5c95528e",
"target": {
"file": "external/lex/luthor.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "133517690763862963477684952232871599946",
"length": 18181
},
"id": "CVE-2026-88344-60932eb1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/jimjag/flatcc/commit/c1dcc8ecd1a74b1e9e724ec7dc98828a5c95528e",
"target": {
"file": "external/lex/luthor.c",
"function": "lex"
}
}
]
"2026-09-25T08:24:17Z"