Libconfuse is a lightweight configuration-file parsing library embedded in various network and system utilities, presenting a narrow but distributed attack surface through its role in the software supply chain. The observed vulnerabilities center on memory-handling weaknesses such as out-of-bounds reads and resource-lifetime management issues, typical of C-based parsing codebases where input validation and allocation tracking are critical. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libconfuse Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40320HIGH cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read. | Sep 9, 2022 | 8.8 | 28 | NO | NO |
CVE-2018-19760HIGH cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak. | Nov 30, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-14447HIGH trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read. | Jul 20, 2018 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libconfuse Project.
Media articles that mention a CVE ID that affects a product developed by Libconfuse Project — matched by CVE ID, not by vendor name.