🔐 CVE Alert

CVE-2026-64198

HIGH 7.8

Out Of Bounds Read in file handling when parsing a .DSB file in DASYLab

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

CWE CWE-125
Vendor measx
Product dasylab
Published Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for measx dasylab

Be the first to know when new high vulnerabilities affecting measx dasylab are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

measX / DASYLab
0 < 2026.0.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
measx.com: https://www.measx.com/en/service/productsecurity/security-updates-for-measx-software/159-securityupdates/1070-out-of-bounds-read-vulnerabilities-in-dasylab-2.html

Credits

measX credits Michael Heinzl for reporting these issues and coordinating disclosure.