CVE-2026-1145 is a critical heap-based buffer overflow vulnerability affecting quickjs-ng quickjs up to version 0.11.0, specifically within the js_typed_array_constructor_ta function in quickjs.c. This flaw allows for remote attacks and has a CVSS score of 8.8 (HIGH), indicating high impact on confidentiality, integrity, and availability. An exploit has been published, making it a significant threat, though it is not yet listed in CISA's KEV catalog. Community discussion is minimal, and there is no media coverage, but a patch (53aebe66170d545bb6265906fe4324e4477de8b4) is available and strongly recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.11.0CPE matchmatch criteria | cpe:2.3:a:quickjs-ng:quickjs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.