CVE-2026-90784
Dvidelabs flatcc semantics.c fb_clear_parser memory leak
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 8dbc3419738da066151991fd2bf1d0c85591dea2. It is suggested to install a patch to address this issue.
| CWE | CWE-401 CWE-404 |
| Vendor | dvidelabs |
| Product | flatcc |
| Published | Sep 14, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for dvidelabs flatcc
Be the first to know when new medium vulnerabilities affecting dvidelabs flatcc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Dvidelabs / flatcc
0.6.0 0.6.1 0.6.2 0.6.3
References
vuldb.com: https://vuldb.com/vuln/403290 vuldb.com: https://vuldb.com/vuln/403290/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90784 vuldb.com: https://vuldb.com/submit/919199 github.com: https://github.com/dvidelabs/flatcc/issues/389 github.com: https://github.com/dvidelabs/flatcc/commit/8dbc3419738da066151991fd2bf1d0c85591dea2 github.com: https://github.com/dvidelabs/flatcc/
Credits
๐ lrrh (VulDB User)