OVERVIEW CVE-2026-35176 is a heap-buffer-overflow read vulnerability in openFPGALoader versions 1.1.1 and earlier that occurs in the POFParser::parseSection() function. The vulnerability allows out-of-bounds heap memory access when processing a maliciously crafted .pof file, and notably does not require FPGA hardware to be triggered. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.1 (HIGH) with a local attack vector requiring user interaction but no special privileges. The impact is significant, with confirmed high confidentiality impact and high availability impact, though integrity is not affected. The relatively high severity reflects the potential for information disclosure and denial of service. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the KEV catalog and is marked as inactive on security watch lists. The EPSS score of 0.00014 indicates exceptionally low exploitation probability in practice, ranking this threat well below average compared to other CVEs. No public exploit code has been reported, and community attention remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.1CPE matchmatch criteria | cpe:2.3:a:trabucayre:openfpgaloader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.