๐Ÿ” CVE Alert

CVE-2026-13573

LOW 3.3

llvm llvm-project ValueSymbolTable ValueSymbolTable.cpp insert stack-based overflow

CVSS Score
3.3
EPSS Score
0.1%
EPSS Percentile
3th

A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.

CWE CWE-121 CWE-119
Vendor llvm
Product llvm-project
Published Jun 29, 2026
Last Updated Jul 7, 2026
Stay Ahead of the Next One

Get instant alerts for llvm llvm-project

Be the first to know when new low vulnerabilities affecting llvm llvm-project are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

llvm / llvm-project
22.1.0 22.1.1 22.1.2 22.1.3 22.1.4 22.1.5 22.1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/374581 vuldb.com: https://vuldb.com/vuln/374581/cti vuldb.com: https://vuldb.com/cve/CVE-2026-13573 vuldb.com: https://vuldb.com/submit/844457 github.com: https://github.com/llvm/llvm-project/issues/199187 github.com: https://github.com/user-attachments/files/28141697/poc.zip github.com: https://github.com/llvm/llvm-project/

Credits

๐Ÿ” TYGLS (VulDB User) VulDB CNA Team