An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema ends with an unterminated quotation mark, the C-string scanning logic in lex() dereferences the input pointer after it has reached the end of the buffer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88345.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88345.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "140745542203207057967600546310812658835",
"length": 18202
},
"id": "CVE-2026-88345-64a435b2",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/jimjag/flatcc/commit/8581715e8ec4e5de8eea9fd6dad949e4dd7d0fa0",
"target": {
"file": "external/lex/luthor.c",
"function": "lex"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"192154736179084535940285208283402335506",
"189758180693956896102618705817941165189",
"291927434774147814907381266111894925547",
"114905508030135431398108895865507993457",
"35200088507735539924784853764467794384",
"59384815895195755758989529845499141338",
"93523947146654348610591918950745400167",
"327517114523189634063938539365658870220",
"333916811758164838247585918942177958953",
"51049710225825284417409462250394150299",
"303204673908176598688439926565812054816",
"126564703287651739028712536449990256161",
"240981646419060854162087877878386343292"
],
"threshold": 0.9
},
"id": "CVE-2026-88345-b6d0062e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/jimjag/flatcc/commit/8581715e8ec4e5de8eea9fd6dad949e4dd7d0fa0",
"target": {
"file": "external/lex/luthor.c"
}
}
]
"2026-09-24T08:26:15Z"