CVE-2025-46687

quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bellard:quickjs:*:*:*:*:*:*:*:*
cpe:2.3:a:quickjs-ng:quickjs:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-27 20:15

Updated : 2026-01-14 17:30


NVD link : CVE-2025-46687

Mitre link : CVE-2025-46687

CVE.ORG link : CVE-2025-46687


JSON object : View

Products Affected

bellard

  • quickjs

quickjs-ng

  • quickjs
CWE
CWE-770

Allocation of Resources Without Limits or Throttling