Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-15888

24
FAUCET Score

CVE-2020-15888 is a critical vulnerability affecting Lua versions through 5.4.0, stemming from improper handling of stack resizes during garbage collection. This flaw can lead to heap-based buffer overflows, over-reads, or use-after-free conditions. Rated 8.8 HIGH, it is remotely exploitable with low attack complexity, potentially resulting in high impact to confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
5.4.0CPE matchmatch criteria
cpe:2.3:a:lua:lua:5.4.0:-:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.45%
Probability of exploitation in next 30 days
EPSS Percentile
82.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0245 is in the 82nd percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 17074-16820Fixed in: 5.3.5-8
microsoftpatch availablevia msrc
Product: 17075-16823Fixed in: 5.3.5-11
microsoftpatch availablevia msrc
Product: 19666-17084Fixed in: 18.2.2-1
microsoftpatch availablevia msrc
Product: cm1 lua 5.3.5-8 on CBL Mariner 1.0Fixed in: 5.3.5-8
microsoftpatch availablevia msrc
Product: cbl2 lua 5.3.5-11 on CBL Mariner 2.0Fixed in: 5.3.5-11
microsoftpatch availablevia msrc
Product: azl3 ceph 18.2.2-8 on Azure Linux 3.0Fixed in: 18.2.2-1

Vendor Advisories (2)

microsoft2020-Jul/CVE-2020-15888Important

Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection leading to a heap-based buffer overflow heap-based buffer over-read or use-after-free.

Jul 14, 2020
redhatCVE-2020-15888Important

lua: stack resizes and garbage collection leads to heap-based buffer overflow

Jul 6, 2020

References

lua-users.org / lists/lua-l/2020-07/msg00053.html
ExploitMailing ListThird Party Advisory
lua-users.org / lists/lua-l/2020-07/msg00054.html
ExploitMailing ListThird Party Advisory
lua-users.org / lists/lua-l/2020-07/msg00071.html
ExploitMailing ListThird Party Advisory
lua-users.org / lists/lua-l/2020-07/msg00079.html
ExploitMailing ListThird Party Advisory
github.com / lua/lua/commit/6298903e35217ab69c279056f925fb72900ce0b7
PatchThird Party Advisory
github.com / lua/lua/commit/eb41999461b6f428186c55abd95f4ce1a76217d5
PatchThird Party Advisory