An indexing error while converting GPT partition names that could read or write beyond a stack-allocated partition entry. (CVE-2026-20345) An integer overflow in the PESpin unpacker that could allocate an undersized buffer and then write beyond it while rebuilding a PE file. (CVE-2026-20339) An integer underflow in the PDF parser that could cause a crash while reading a malformed hex string. (CVE-2026-20346) Undefined behavior and integer overflow in the Mach-O parser that could cause a crash while scanning a malformed Mach-O file. (CVE-2026-20347) XAR parser size handling that could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. (CVE-2026-20348)