🔐 CVE Alert

CVE-2026-64196

HIGH 7.8

Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

CWE CWE-787
Vendor measx
Product dasylab
Published Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for measx dasylab

Be the first to know when new high vulnerabilities affecting measx dasylab are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

measX / DASYLab
0 < 2026.0.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
measx.com: https://www.measx.com/en/service/productsecurity/security-updates-for-measx-software/159-securityupdates/1071-out-of-bounds-write-vulnerabilities-in-dasylab-2.html

Credits

measX credits Michael Heinzl for reporting these issues and coordinating disclosure.