CVE-2026-10268
A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_fiber of the file src
CVSS
3.3
Low
EPSS
0.1%
p2
KEV
—
Exploit Today
1
0-100
Published: Jun 1, 2026 · Last modified: Jul 22, 2026 · CWE-189 · CWE-190
0.1%EPSS · 30 days0.1%
2026-08-032026-08-31
A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_fiber of the file src/core/marsh.c. Executing a manipulation can lead to integer overflow. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. This patch is called d9b1d711ea1fde52ac73a82088b512a3e17bad0d. A patch should be applied to remediate this issue.
- github.comhttps://github.com/biniamf/pocs/tree/main/janet-marsh-unmarshal-intovf
- github.comhttps://github.com/janet-lang/janet/
- github.comhttps://github.com/janet-lang/janet/commit/d9b1d711ea1fde52ac73a82088b512a3e17bad0d
- github.comhttps://github.com/janet-lang/janet/issues/1744
- vuldb.comhttps://vuldb.com/cve/CVE-2026-10268
- vuldb.comhttps://vuldb.com/submit/825075
- vuldb.comhttps://vuldb.com/vuln/367547
- vuldb.comhttps://vuldb.com/vuln/367547/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-824807.4 HIG12.9%
——4A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.17hCVE-2026-547559.6 CRI31.6%
——9Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckValid100Params. Royalty payout paths in core/kapp/accounts/accounts.go, core/kapp/market/market.go, and core/kapp/ito/ito.go then credit each oversized split amount and silently discard a negative remainder, allowing ordinary asset transfers, marketplace purchases, or ITO purchases to create unbacked KLV or other assets. This issue is fixed in version 1.7.19.16hCVE-2026-19313—38.9%
——12An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.3dCVE-2026-383507.5 HIG24.9%
——7An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.4dCVE-2026-383497.5 HIG24.9%
——7An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.4dCVE-2026-383487.5 HIG24.9%
——7An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.4d