Dvidelabs flatcc Struct Analysis semantics.c analyze_struct assertion
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/compiler/semantics.c of the component Struct Analysis. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit has been made public and could be used. The patch is identified as f705032346ee39efd7d3848c50b73d455d28d06d. A patch should be applied to remediate this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
Dvidelabs · flatccpublic PoCs found — 1
cve_referencegithub.com/dvidelabs/flatcc/issues/388unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/dvidelabs/flatcc/https://github.com/dvidelabs/flatcc/commit/f705032346ee39efd7d3848c50b73d455d28d06dhttps://github.com/dvidelabs/flatcc/issues/388https://vuldb.com/cve/CVE-2026-90785https://vuldb.com/submit/919200https://vuldb.com/vuln/403291https://vuldb.com/vuln/403291/cti