CVE-2026-0822 is a heap-based buffer overflow vulnerability affecting quickjs-ng quickjs versions up to 0.11.0, specifically within the js_typed_array_sort function in quickjs.c. This flaw carries a high severity CVSS score of 8.8, indicating it can be exploited remotely with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. While not currently on the CISA KEV catalog, a public exploit is available, increasing the risk of exploitation despite minimal community discussion or media coverage. Organizations using affected quickjs versions should apply the provided patch (53eefbcd695165a3bd8c584813b472cb4a69fbf5) immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.11.0CPE matchmatch criteria | cpe:2.3:a:quickjs-ng:quickjs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.