CVE-2026-1998 is a memory corruption vulnerability affecting MicroPython versions up to 1.27.0, specifically within the mp_import_all function in py/runtime.c. This flaw can be exploited locally by an authenticated attacker, leading to a denial of service due to memory corruption. While a public exploit exists, there is no evidence of active exploitation, and it has garnered minimal community discussion or media coverage. The CVSS score of 5.5 (Medium) reflects its local attack vector and high impact on availability, with a FAUCET Risk Score of 83/100 indicating a significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.27.0CPE matchmatch criteria | cpe:2.3:a:micropython:micropython:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.