CVE-2026-88355

Source
https://cve.org/CVERecord?id=CVE-2026-88355
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88355.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-88355
Published
2026-09-24T00:00:00Z
Modified
2026-09-26T08:05:08Z
Summary
[none]
Details

An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function allocates less memory than sizeof(te_expr) but treats the returned allocation as a complete te_expr object. This results in undefined behavior and can cause deterministic process termination in UBSan-instrumented builds.

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88355.json"
}
References

Affected packages

Git / github.com/szaydel/tinyexpr

Affected ranges

Type
GIT
Repo
https://github.com/szaydel/tinyexpr
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88355.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "328501302803661730252761329592220338325",
                "30229056534046461085818270848024266989",
                "3107057848197806472077546343778336183",
                "241973780648151657723568189387079775361"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-88355-0dda26d9",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b",
        "target":  {
            "file":  "tinyexpr.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "9847663013638542663353395907742480339",
            "length":  479
        },
        "id":  "CVE-2026-88355-b0d34760",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b",
        "target":  {
            "file":  "tinyexpr.c",
            "function":  "new_expr"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "52760609968046561809843419364735674836",
                "240354706997081154450127997360094328769",
                "318978910677225100876928235940698025718",
                "143645653040372076205694005715644119143"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-88355-cdf148b7",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b",
        "target":  {
            "file":  "tinyexpr.h"
        }
    }
]
vanir_signatures_modified
"2026-09-26T08:05:08Z"