πŸ” CVE Alert

CVE-2026-42199

MEDIUM 6.2

Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior

CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th

Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand_rows() can corrupt the relationship between the grid’s logical dimensions and its backing storage. After the internal invariant is broken, the safe API get() may invoke get_unchecked() with an invalid index, resulting in Undefined Behavior. This issue has been patched in version 1.0.1.

CWE CWE-190
Vendor becheran
Product grid
Published May 8, 2026
Stay Ahead of the Next One

Get instant alerts for becheran grid

Be the first to know when new medium vulnerabilities affecting becheran grid are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

becheran / grid
>= 0.17.0, < 1.0.1

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/becheran/grid/security/advisories/GHSA-38c5-483c-4qqp github.com: https://github.com/becheran/grid/commit/be213bd3528727148bef2d523c89e95d1fd9c072 github.com: https://github.com/becheran/grid/releases/tag/v1.0.1