Lily Lang is a programming language implementation with a narrow but specialized vulnerability footprint centered on the language runtime itself. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lily Lang over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2660HIGH A vulnerability was identified in FascinatedBox lily up to 2.3. Affected by this issue is the function shorthash_for_name of the file src/lily_symtab.c. The manipulation leads to u | Feb 18, 2026 | 7.8 | 24 | NO | NO |
CVE-2026-2662HIGH A weakness has been identified in FascinatedBox lily up to 2.3. This vulnerability affects the function count_transforms of the file src/lily_emitter.c. This manipulation causes ou | Feb 18, 2026 | 7.8 | 23 | NO | NO |
CVE-2026-3391MEDIUM A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-boun | Mar 1, 2026 | 5.5 | 20 | NO | NO |
CVE-2026-3392MEDIUM A weakness has been identified in FascinatedBox lily up to 2.3. The affected element is the function eval_tree of the file src/lily_emitter.c. This manipulation causes null pointer | Mar 1, 2026 | 5.5 | 18 | NO | NO |
CVE-2026-3390MEDIUM A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error Reporting. | Mar 1, 2026 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lily Lang.
Media articles that mention a CVE ID that affects a product developed by Lily Lang — matched by CVE ID, not by vendor name.