{"id":"CVE-2026-3285","summary":"berry-lang berry be_lexer.c scan_string out-of-bounds","details":"A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the file src/be_lexer.c. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: 7149c59a39ba44feca261b12f06089f265fec176. Applying a patch is the recommended action to fix this issue.","modified":"2026-08-12T15:32:29.862272Z","published":"2026-02-27T03:02:13.772Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3285.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/berry-lang/berry/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3285.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3285"},{"type":"ADVISORY","url":"https://vuldb.com/?id.348014"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.758872"},{"type":"REPORT","url":"https://github.com/berry-lang/berry/issues/509"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.348014"},{"type":"FIX","url":"https://github.com/berry-lang/berry/commit/7149c59a39ba44feca261b12f06089f265fec176"},{"type":"FIX","url":"https://github.com/berry-lang/berry/pull/511"},{"type":"EVIDENCE","url":"https://github.com/oneafter/0211/blob/main/be/repro"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/berry-lang/berry","events":[{"introduced":"b5ede66721937533fbf5c286ef44a5111ea30c75"},{"fixed":"7149c59a39ba44feca261b12f06089f265fec176"}],"database_specific":{"cpe":"cpe:2.3:a:berry-lang:berry:1.1.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.1.0"},{"last_affected":"1.1.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.1.0","v1.1.0"],"database_specific":{"vanir_signatures_modified":"2026-08-12T15:32:29Z","vanir_signatures":[{"target":{"file":"src/be_lexer.c","function":"scan_string"},"deprecated":false,"digest":{"function_hash":"171909988789556060815880846552433693707","length":527},"id":"CVE-2026-3285-0af35d71","signature_type":"Function","signature_version":"v1","source":"https://github.com/berry-lang/berry/commit/7149c59a39ba44feca261b12f06089f265fec176"},{"deprecated":false,"digest":{"line_hashes":["158807579498153835044010150474020024592","196127997163451423732466084733066000552","326115317715822798537160605998773527020","284513134435939560701406010489424611567"],"threshold":0.9},"id":"CVE-2026-3285-3b3d83b7","signature_type":"Line","signature_version":"v1","source":"https://github.com/berry-lang/berry/commit/7149c59a39ba44feca261b12f06089f265fec176","target":{"file":"src/be_lexer.c"}},{"id":"CVE-2026-3285-e638f329","signature_type":"Line","signature_version":"v1","source":"https://github.com/berry-lang/berry/commit/7149c59a39ba44feca261b12f06089f265fec176","target":{"file":"src/be_strlib.c"},"deprecated":false,"digest":{"line_hashes":["200123996703519491286523834886868032691","264960970511847308578059668493816500019","144918738726185877807504602889873033344","106659540769191730938905014706470239641","289912598733419863931404018143882904519","243748564966822156717794339939290823973","30295754120311536244214602692123550702","260090756479401332349881312885170561153","104401179505788755898332766053001361639","47624470960068159401329109252413971309","136577907361952520390700692552107287751","256707749711657831059748781685047294057"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"42461745822142710209225595774792749759","length":421},"id":"CVE-2026-3285-efce2278","signature_type":"Function","signature_version":"v1","source":"https://github.com/berry-lang/berry/commit/7149c59a39ba44feca261b12f06089f265fec176","target":{"file":"src/be_strlib.c","function":"get_mode"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3285.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}]}