CVE-2026-90784

Source
https://cve.org/CVERecord?id=CVE-2026-90784
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90784.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90784
Published
2026-09-14T13:00:10Z
Modified
2026-09-16T08:09:46Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Dvidelabs flatcc semantics.c fb_clear_parser memory leak
Details

A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 8dbc3419738da066151991fd2bf1d0c85591dea2. It is suggested to install a patch to address this issue.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-401",
        "CWE-404"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90784.json"
}
References

Affected packages

Git / github.com/dvidelabs/flatcc

Affected ranges

Type
GIT
Repo
https://github.com/dvidelabs/flatcc
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.6.0"
        },
        {
            "last_affected":  "0.6.0"
        },
        {
            "introduced":  "0.6.1"
        },
        {
            "last_affected":  "0.6.1"
        },
        {
            "introduced":  "0.6.2"
        },
        {
            "last_affected":  "0.6.2"
        },
        {
            "introduced":  "0.6.3"
        },
        {
            "last_affected":  "0.6.3"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.6.0
0.6.1
0.6.2
0.6.3
v0.*
v0.6.0
v0.6.1
v0.6.2
v0.6.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90784.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "315884164663978118094176203720649870576",
            "length":  1346
        },
        "id":  "CVE-2026-90784-38ff46a7",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/dvidelabs/flatcc/commit/8dbc3419738da066151991fd2bf1d0c85591dea2",
        "target":  {
            "file":  "src/compiler/parser.c",
            "function":  "fb_clear_parser"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "193589990907770061225332855166406767832",
                "298303858113253097711473146746693378229",
                "284314020853870534490371577101520488229",
                "163646356158272060661613926731413695025"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-90784-c9b580f2",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/dvidelabs/flatcc/commit/8dbc3419738da066151991fd2bf1d0c85591dea2",
        "target":  {
            "file":  "src/compiler/parser.c"
        }
    }
]
vanir_signatures_modified
"2026-09-16T08:09:46Z"