{"id":"CVE-2026-24817","summary":"A potential heap-buffer overflow in praydog/UEVR","details":"Out-of-bounds Write vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C.\n\nThis issue affects UEVR: before 1.05.","modified":"2026-08-12T15:31:48.354692Z","published":"2026-01-27T08:53:44.618Z","database_specific":{"cna_assigner":"GovTech CSG","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24817.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24817.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24817"},{"type":"FIX","url":"https://github.com/praydog/UEVR/pull/336"},{"type":"PACKAGE","url":"https://github.com/praydog/UEVR"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/praydog/uevr","events":[{"introduced":"0"},{"fixed":"1a810f69fe4cab82b352c574763959d4390b84ce"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.05"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["1.04","1.03","1.02","1.01","1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24817.json","vanir_signatures_modified":"2026-08-12T15:31:48Z","vanir_signatures":[{"source":"https://github.com/praydog/uevr/commit/1a810f69fe4cab82b352c574763959d4390b84ce","target":{"file":"lua-api/lib/src/ScriptContext.cpp","function":"ScriptContext::setup_bindings"},"deprecated":false,"digest":{"function_hash":"216866318178216783764247029443971656225","length":32139},"id":"CVE-2026-24817-3c108d57","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/praydog/uevr/commit/1a810f69fe4cab82b352c574763959d4390b84ce","target":{"file":"lua-api/lib/include/ScriptUtility.hpp"},"deprecated":false,"digest":{"line_hashes":["76689799006253686248220292398518621845","314803333986411688827142784283464790289"],"threshold":0.9},"id":"CVE-2026-24817-eb8d7c95"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["312892543692814921776954288577817648298","47396217611344227271283426539206311635","150787503396620570941209381962416646457","79981182897563887704213221120619060923","275367409753962000637729972485649590557","202664839936022055803655280171210740086","105385815761475094117147550383245447909","301285475895534476966058108554863286777","321906523048421178410954724004431863931","184309246528067729036184709238780710435","185949753380040380980004399407346201193","326788411745635735583482286663976525704","237072619546160956074229702866146629499","193707850202347402890076628680703897656","59991138865232857780907529588978398795","86628096864037125615437956980371970957","268481362697083102605574460294337897882","321846445648654536091696323317941062653","17471863292212087693465056768407991475","32889407753790754453063082317851240205","262510987908002256380026400091047084896"]},"id":"CVE-2026-24817-fab29d0a","signature_type":"Line","signature_version":"v1","source":"https://github.com/praydog/uevr/commit/1a810f69fe4cab82b352c574763959d4390b84ce","target":{"file":"lua-api/lib/src/ScriptContext.cpp"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/S:N/AU:Y/R:U/V:D/RE:M/U:Amber"}]}