CVE-2026-4010 identifies a memory corruption vulnerability within the pkByteBufferAddString function of ThakeeNathees pocketlang, affecting versions up to commit cc73ca61b113d48ee130d837a7a8b145e41de5ce. This low-severity flaw (CVSS 3.1: 3.3) requires local access for exploitation and could result in a denial of service or application crash. Although there is no evidence of active exploitation or significant community discussion, public exploit code is available, which increases the potential for future attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ThakeeNathees | Pocketlang | cc73ca61b113d48ee130d837a7a8b145e41de5ceCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.