🔐 CVE Alert

CVE-2026-29079

UNKNOWN 0.0

Type Confusion in Lexbor Fragment Parser

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the qualified_name field. That corrupted value is later used as a pointer and dereferenced near the zero page. This vulnerability is fixed in 2.7.0.

CWE CWE-843
Vendor lexbor
Product lexbor
Published Mar 13, 2026
Last Updated Mar 16, 2026
Stay Ahead of the Next One

Get instant alerts for lexbor lexbor

Be the first to know when new unknown vulnerabilities affecting lexbor lexbor are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

lexbor / lexbor
< 2.7.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/lexbor/lexbor/security/advisories/GHSA-mrpr-v36q-2vp8