CVE-2026-2903 is a low-severity vulnerability affecting skvadrik re2c versions up to 4.4, specifically within the check_and_merge_special_rules function in src/parse/ast.cc. This flaw allows for a local attacker to cause a null pointer dereference, leading to a denial of service. The CVSS score is 3.3, indicating a low impact with local access required and no user interaction. While an exploit has been published, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Skvadrik | Re2c | 4.0, 4.1, 4.2, 4.3, 4.4CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.