CVE-2026-86315
CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th
An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX. This issue affects Escargot: 5dc93606abd42b859045add05d704a038e197359.
| CWE | CWE-197 |
| Vendor | samsung opensource |
| Product | escargot |
| Published | Sep 7, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for samsung opensource escargot
Be the first to know when new medium vulnerabilities affecting samsung opensource escargot are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
Samsung Opensource / Escargot
5dc93606abd42b859045add05d704a038e197359
References
Credits
p4p3r of μΈμ΄λ²μ