CVE-2026-13573
llvm llvm-project ValueSymbolTable ValueSymbolTable.cpp insert stack-based overflow
CVSS Score
3.3
EPSS Score
0.1%
EPSS Percentile
3th
A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.
| CWE | CWE-121 CWE-119 |
| Vendor | llvm |
| Product | llvm-project |
| Published | Jun 29, 2026 |
| Last Updated | Jul 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for llvm llvm-project
Be the first to know when new low vulnerabilities affecting llvm llvm-project are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
llvm / llvm-project
22.1.0 22.1.1 22.1.2 22.1.3 22.1.4 22.1.5 22.1.6
References
vuldb.com: https://vuldb.com/vuln/374581 vuldb.com: https://vuldb.com/vuln/374581/cti vuldb.com: https://vuldb.com/cve/CVE-2026-13573 vuldb.com: https://vuldb.com/submit/844457 github.com: https://github.com/llvm/llvm-project/issues/199187 github.com: https://github.com/user-attachments/files/28141697/poc.zip github.com: https://github.com/llvm/llvm-project/
Credits
๐ TYGLS (VulDB User) VulDB CNA Team