CVE-2026-10268

Published: Giu 01, 2026 Last Modified: Giu 01, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 1,9
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW 3,3
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: low
LOW 1,7
Access Vector: local
Access Complexity: low
Authentication: single
Confidentiality: none
Integrity: none
Availability: partial

Description

AI Translation Available

A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_fiber of the file src/core/marsh.c. Executing a manipulation can lead to integer overflow. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. This patch is called d9b1d711ea1fde52ac73a82088b512a3e17bad0d. A patch should be applied to remediate this issue.

190

Integer Overflow or Wraparound

Stable
Common Consequences
Security Scopes Affected:
Availability Integrity Confidentiality Access Control Other
Potential Impacts:
Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Memory) Dos: Instability Modify Memory Execute Unauthorized Code Or Commands Bypass Protection Mechanism Alter Execution Logic Dos: Resource Consumption (Cpu)
Applicable Platforms
Languages: Not Language-Specific, C
View CWE Details
https://github.com/biniamf/pocs/tree/main/janet-marsh-unmarshal-intovf
https://github.com/janet-lang/janet/
https://github.com/janet-lang/janet/commit/d9b1d711ea1fde52ac73a82088b512a3e17b…
https://github.com/janet-lang/janet/issues/1744
https://vuldb.com/cve/CVE-2026-10268
https://vuldb.com/submit/825075
https://vuldb.com/vuln/367547
https://vuldb.com/vuln/367547/cti