{"id":"CVE-2026-2259","summary":"aardappel lobster Parsing parser.h ParseStatements memory corruption","details":"A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The identifier of the patch is 2f45fe860d00990e79e13250251c1dde633f1f89. Applying a patch is the recommended action to fix this issue.","modified":"2026-08-12T15:31:39.738202Z","published":"2026-02-10T02:32:08.234Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2259.json"},"references":[{"type":"WEB","url":"https://github.com/aardappel/lobster/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2259.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2259"},{"type":"ADVISORY","url":"https://vuldb.com/?id.345006"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.753168"},{"type":"REPORT","url":"https://github.com/aardappel/lobster/issues/396"},{"type":"REPORT","url":"https://github.com/aardappel/lobster/issues/396#issuecomment-3849019040"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.345006"},{"type":"FIX","url":"https://github.com/aardappel/lobster/commit/2f45fe860d00990e79e13250251c1dde633f1f89"},{"type":"EVIDENCE","url":"https://github.com/oneafter/0204/blob/main/lob2/repro.lobster"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aardappel/lobster","events":[{"introduced":"0"},{"fixed":"2f45fe860d00990e79e13250251c1dde633f1f89"}],"database_specific":{"cpe":"cpe:2.3:a:strlen:lobster:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2025.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2025.0","2025.1","2025.2","2025.3","2025.4","v2025.4","v2025.3","v2025.2","v2025.1","v2025.0","v2024.0","v2023.13","v2023.12","before_namespace_change","v2023.10","v2023.9","v2023.8","v2023.7","v2023.6","v2023.5","v2023.4","v2023.2","v2021.3","v2021.1","v2021.0","last_wasm_generator_enabled","last_interpreter","last_coroutine","last_frame_log","lastruntimerefc","last_dynamically_typed"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2259.json","vanir_signatures_modified":"2026-08-12T15:31:39Z","vanir_signatures":[{"target":{"file":"dev/src/lobster/parser.h"},"deprecated":false,"digest":{"line_hashes":["14431847067098788917002389626945123796","198016880518592490858131099026057322917","299841096168451569541472544696957966366","267498294270574172788541796230356870511","70106359949407829395778539218672129610","9168717164632508204389848901840988727","198852430302128499859780812772647066979","16988111020498090564702997369260342090"],"threshold":0.9},"id":"CVE-2026-2259-e795595a","signature_type":"Line","signature_version":"v1","source":"https://github.com/aardappel/lobster/commit/2f45fe860d00990e79e13250251c1dde633f1f89"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}