An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function allocates less memory than sizeof(te_expr) but treats the returned allocation as a complete te_expr object. This results in undefined behavior and can cause deterministic process termination in UBSan-instrumented builds.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88355.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88355.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"328501302803661730252761329592220338325",
"30229056534046461085818270848024266989",
"3107057848197806472077546343778336183",
"241973780648151657723568189387079775361"
],
"threshold": 0.9
},
"id": "CVE-2026-88355-0dda26d9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b",
"target": {
"file": "tinyexpr.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "9847663013638542663353395907742480339",
"length": 479
},
"id": "CVE-2026-88355-b0d34760",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b",
"target": {
"file": "tinyexpr.c",
"function": "new_expr"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"52760609968046561809843419364735674836",
"240354706997081154450127997360094328769",
"318978910677225100876928235940698025718",
"143645653040372076205694005715644119143"
],
"threshold": 0.9
},
"id": "CVE-2026-88355-cdf148b7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b",
"target": {
"file": "tinyexpr.h"
}
}
]
"2026-09-26T08:05:08Z"