Luajit is a lightweight, high-performance just-in-time compiler for Lua that is embedded across a wide range of applications, game engines, and systems software despite its narrow product footprint, making its vulnerability profile consequential out of proportion to its volume. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety weakness classes including out-of-bounds reads, type confusion, NULL-pointer dereferences, and stack-based buffer overflows, reflecting the low-level code-generation and runtime demands of a JIT compiler. Defenders should inventory upstream products that bundle this library and treat Luajit updates as supply-chain dependencies; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Luajit over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25176CRITICAL LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c. | Jul 7, 2025 | 9.8 | 28 | NO | NO |
CVE-2020-15890HIGH LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled. | Jul 21, 2020 | 7.5 | 27 | NO | NO |
CVE-2019-19391CRITICAL In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations, becau | Nov 29, 2019 | 9.1 | 26 | NO | NO |
CVE-2024-25178CRITICAL LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c. | Jul 7, 2025 | 9.1 | 24 | NO | NO |
CVE-2020-24372HIGH LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c. | Aug 17, 2020 | 7.5 | 23 | NO | NO |
CVE-2024-25177HIGH LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS). | Jul 7, 2025 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Luajit.
Media articles that mention a CVE ID that affects a product developed by Luajit — matched by CVE ID, not by vendor name.