CVE-2026-1145
Last modified
CVE-2026-1145 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 53aebe66170d545bb6265906fe4324e4477de8b4. It is suggested to install a patch to address this issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Quickjs-Ng | Quickjs | <= 0.11.0 |
References
- https://github.com/quickjs-ng/quickjs/issues/1305Exploit, Issue Tracking
- https://github.com/quickjs-ng/quickjs/issues/1305#issue-3785444372Exploit, Issue Tracking
- https://github.com/quickjs-ng/quickjs/pull/1306Issue Tracking, Patch
- https://vuldb.com/?ctiid.341738Permissions Required, VDB Entry
- https://vuldb.com/?id.341738Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.735539Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-1145?
How severe is CVE-2026-1145?
How do I fix CVE-2026-1145?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-11442Allegra exportReport Directory Traversal Information Disclos…6.5
- CVE-2026-11443Allegra downloadAttachment Cross-Site Scripting Authenticati…4.6
- CVE-2026-11446The Booktics – Booking Calendar for Appointments and Service…5.3
- CVE-2026-11447A security flaw has been discovered in GL.iNet GL-MT3000 up …6.3
- CVE-2026-11448A weakness has been identified in GL.iNet GL-MT3000 up to 4.…5.1
- CVE-2026-11449A security vulnerability has been detected in GL.iNet GL-MT3…6.3
- CVE-2026-11450A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. Thi…7.3
- CVE-2026-11451A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impac…7.3
- CVE-2026-11452A vulnerability has been found in GL.iNet GL-MT3000 up to 4.…7.3
- CVE-2026-11453A vulnerability was found in Tiobon Employee Self-Service Sy…6.3
- CVE-2026-11454The Groundhogg — CRM, Newsletters, and Marketing Automation …6.5
- CVE-2026-11455A vulnerability was determined in FoundationAgents MetaGPT u…5
Are you affected by CVE-2026-1145?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
