{"id":"CVE-2026-4734","summary":"Heap Buffer Overflow in yoyofr/modizer","details":"Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt/openmpt-trunk/include/premake/contrib/curl/lib modules). This vulnerability is associated with program files imap.C\u200e.\n\nThis issue affects modizer: before v4.3.","modified":"2026-07-15T01:48:53.413843229Z","published":"2026-03-24T03:05:39.360Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4734.json","cna_assigner":"GovTech CSG","cwe_ids":["CWE-119"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4734.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4734"},{"type":"FIX","url":"https://github.com/yoyofr/modizer/pull/141"},{"type":"PACKAGE","url":"https://github.com/yoyofr/modizer"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yoyofr/modizer","events":[{"introduced":"0"},{"fixed":"ace8221f71829777dc2b208d0557085d4f63becb"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"v4.3"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["4.2","4.1.1","3.7.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4734.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/S:N/AU:Y/R:U/V:D/RE:L/U:Clear"}]}