CVE-2026-88345

Source
https://cve.org/CVERecord?id=CVE-2026-88345
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88345.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-88345
Published
2026-09-22T00:00:00Z
Modified
2026-09-24T08:26:15Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema ends with an unterminated quotation mark, the C-string scanning logic in lex() dereferences the input pointer after it has reached the end of the buffer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88345.json"
}
References

Affected packages

Git / github.com/jimjag/flatcc

Affected ranges

Type
GIT
Repo
https://github.com/jimjag/flatcc
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.2.0
v0.2.1
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.5a
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88345.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "140745542203207057967600546310812658835",
            "length":  18202
        },
        "id":  "CVE-2026-88345-64a435b2",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/jimjag/flatcc/commit/8581715e8ec4e5de8eea9fd6dad949e4dd7d0fa0",
        "target":  {
            "file":  "external/lex/luthor.c",
            "function":  "lex"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "192154736179084535940285208283402335506",
                "189758180693956896102618705817941165189",
                "291927434774147814907381266111894925547",
                "114905508030135431398108895865507993457",
                "35200088507735539924784853764467794384",
                "59384815895195755758989529845499141338",
                "93523947146654348610591918950745400167",
                "327517114523189634063938539365658870220",
                "333916811758164838247585918942177958953",
                "51049710225825284417409462250394150299",
                "303204673908176598688439926565812054816",
                "126564703287651739028712536449990256161",
                "240981646419060854162087877878386343292"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-88345-b6d0062e",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/jimjag/flatcc/commit/8581715e8ec4e5de8eea9fd6dad949e4dd7d0fa0",
        "target":  {
            "file":  "external/lex/luthor.c"
        }
    }
]
vanir_signatures_modified
"2026-09-24T08:26:15Z"