CVE-2026-90784
A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 8dbc3419738da066151991fd2bf1d0c85591dea2. It is suggested to install a patch to address this issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.42%
- CWE
- CWE-401, CWE-404
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- Dvidelabs flatcc
- Dvidelabs flatcc
- Dvidelabs flatcc
- Dvidelabs flatcc
Weakness type
Related vulnerabilities
- CVE-2026-3650 — Grassroots DICOM Missing release of memory after effective lifetime
- CVE-2025-61974 — BIG-IP SSL/TLS vulnerability
- CVE-2025-30658 — Junos OS: SRX Series: On devices with Anti-Virus enabled, malicious server responses will cause memory to leak ultimately causing forwarding to stop
- CVE-2025-21599 — Junos OS Evolved: Receipt of specifically malformed IPv6 packets causes kernel memory exhaustion leading to Denial of Service
- CVE-2025-21091 — BIG-IP SNMP vulnerability
- CVE-2025-14027 — Rockwell Automation Recommends Upgrading From 1756-RM2 XT To 1756-RM3 XT
- CVE-2024-39549 — Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak
- CVE-2024-20304 — Cisco IOS XR Software Packet Memory Exhaustion Vulnerability