Lexbor is a lightweight HTML parsing library whose vulnerabilities center on memory-safety and type-handling issues such as type confusion, integer underflow, and out-of-bounds writes—exposures that arise from the parsing complexity inherent to HTML processing. Treat this as a focused library vendor whose risk profile depends on breadth of downstream integration rather than volume of disclosures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lexbor over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29079HIGH Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unk | Mar 13, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-29078HIGH Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary size variable between iterations. The statement ctx->buffer_u | Mar 13, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lexbor.
Media articles that mention a CVE ID that affects a product developed by Lexbor — matched by CVE ID, not by vendor name.