OSV-2026-726

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/md4c/OSV-2026-726.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2026-726
Published
2026-05-14T00:02:58.367907Z
Modified
2026-05-14T00:02:58.368281Z
Summary
Use-after-poison in md_build_attribute
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=512429151

Crash type: Use-after-poison READ 1
Crash state:
md_build_attribute
md_process_all_blocks
md_parse
References

Affected packages

OSS-Fuzz / md4c

Package

Name
md4c
Purl
pkg:generic/md4c

Affected ranges

Type
GIT
Repo
https://github.com/mity/md4c
Events

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

introduced_range
"07712a59a4cdb66170d608125ce3a191ffa3d4c7:345666722d965072c2c94bbb08b2ae91385c1592"
fixed_range
"4f0b252c8e8952d53156949777ebfe3f9355def3:5f9b246fd01e90afa8075c1b6c2904ea44375fe3"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/md4c/OSV-2026-726.yaml"