{"id":"CVE-2026-2016","summary":"happyfish100 libfastcommon base64.c base64_decode stack-based overflow","details":"A security vulnerability has been detected in happyfish100 libfastcommon up to 1.0.84. Affected by this vulnerability is the function base64_decode of the file src/base64.c. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The identifier of the patch is 82f66af3e252e3e137dba0c3891570f085e79adf. Applying a patch is the recommended action to fix this issue.","modified":"2026-07-15T01:49:11.010343768Z","published":"2026-02-06T11:02:08.107Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2016.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.0.0"},{"last_affected":"1.0.0"},{"introduced":"1.0.1"},{"last_affected":"1.0.1"},{"introduced":"1.0.2"},{"last_affected":"1.0.2"},{"introduced":"1.0.3"},{"last_affected":"1.0.3"},{"introduced":"1.0.4"},{"last_affected":"1.0.4"},{"introduced":"1.0.5"},{"last_affected":"1.0.5"},{"introduced":"1.0.6"},{"last_affected":"1.0.6"},{"introduced":"1.0.8"},{"last_affected":"1.0.8"},{"introduced":"1.0.9"},{"last_affected":"1.0.9"},{"introduced":"1.0.10"},{"last_affected":"1.0.10"},{"introduced":"1.0.11"},{"last_affected":"1.0.11"},{"introduced":"1.0.12"},{"last_affected":"1.0.12"},{"introduced":"1.0.13"},{"last_affected":"1.0.13"},{"introduced":"1.0.14"},{"last_affected":"1.0.14"},{"introduced":"1.0.15"},{"last_affected":"1.0.15"},{"introduced":"1.0.16"},{"last_affected":"1.0.16"},{"introduced":"1.0.17"},{"last_affected":"1.0.17"},{"introduced":"1.0.18"},{"last_affected":"1.0.18"},{"introduced":"1.0.19"},{"last_affected":"1.0.19"},{"introduced":"1.0.20"},{"last_affected":"1.0.20"},{"introduced":"1.0.21"},{"last_affected":"1.0.21"},{"introduced":"1.0.22"},{"last_affected":"1.0.22"},{"introduced":"1.0.23"},{"last_affected":"1.0.23"},{"introduced":"1.0.24"},{"last_affected":"1.0.24"},{"introduced":"1.0.25"},{"last_affected":"1.0.25"},{"introduced":"1.0.26"},{"last_affected":"1.0.26"},{"introduced":"1.0.27"},{"last_affected":"1.0.27"},{"introduced":"1.0.28"},{"last_affected":"1.0.28"},{"introduced":"1.0.29"},{"last_affected":"1.0.29"},{"introduced":"1.0.30"},{"last_affected":"1.0.30"},{"introduced":"1.0.31"},{"last_affected":"1.0.31"},{"introduced":"1.0.32"},{"last_affected":"1.0.32"},{"introduced":"1.0.33"},{"last_affected":"1.0.33"},{"introduced":"1.0.34"},{"last_affected":"1.0.34"},{"introduced":"1.0.46"},{"last_affected":"1.0.46"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-121"]},"references":[{"type":"WEB","url":"https://github.com/happyfish100/libfastcommon/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2016.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2016"},{"type":"ADVISORY","url":"https://vuldb.com/?id.344598"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.743873"},{"type":"REPORT","url":"https://github.com/happyfish100/libfastcommon/issues/55"},{"type":"REPORT","url":"https://github.com/happyfish100/libfastcommon/issues/55#issue-3836362577"},{"type":"REPORT","url":"https://github.com/happyfish100/libfastcommon/issues/55#issuecomment-3776757848"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.344598"},{"type":"FIX","url":"https://github.com/happyfish100/libfastcommon/commit/82f66af3e252e3e137dba0c3891570f085e79adf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/happyfish100/libfastcommon","events":[{"introduced":"0"},{"fixed":"82f66af3e252e3e137dba0c3891570f085e79adf"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.0.84"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:happyfish100:libfastcommon:*:*:*:*:*:*:*:*"}}],"versions":["1.0.35","1.0.36","1.0.37","1.0.38","1.0.39","1.0.40","1.0.41","1.0.42","1.0.43","1.0.44","1.0.45","1.0.47","1.0.48","1.0.49","1.0.50","1.0.51","1.0.52","1.0.53","1.0.54","1.0.55","1.0.56","1.0.57","1.0.58","1.0.59","1.0.60","1.0.61","1.0.62","1.0.63","1.0.64","1.0.65","1.0.66","1.0.67","1.0.68","1.0.69","1.0.7","1.0.70","1.0.71","1.0.72","1.0.73","1.0.74","1.0.75","1.0.76","1.0.77","1.0.78","1.0.79","1.0.80","1.0.81","1.0.82","1.0.83","1.0.84","V1.0.84","V1.0.83","V1.0.82","V1.0.81","V1.0.80","V1.0.79","V1.0.78","V1.0.77","V1.0.75","V1.0.74","V1.0.73","V1.0.72","V1.0.71","V1.0.70","V1.0.69","V1.0.68","V1.0.67","V1.0.66","V1.0.65","V1.0.64","V1.0.63","V1.0.62","V1.0.61","V1.0.60","V1.0.59","V1.0.58","V1.0.57","V1.0.56","V1.0.55","V1.0.54","V1.0.53","V1.0.52","V1.0.51","V1.0.50","V1.0.49","V1.0.48","V1.0.47","V1.0.45","V1.0.44","V1.0.43","V1.0.42","V1.0.41","V1.0.40","V1.0.39","V1.0.38","V1.0.37","V1.0.36","V1.0.35","V1.0.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2016.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}