{"id":"CVE-2026-4743","summary":"Null-Pointer Dereference Vulnerability in taurusxin/ncmdump","details":"NULL Pointer Dereference vulnerability in taurusxin ncmdump (\u200esrc/utils\u200e modules). This vulnerability is associated with program files cJSON.Cpp\u200e.\n\nThis issue affects ncmdump: before 1.4.0.","modified":"2026-07-21T23:33:37.880243Z","published":"2026-03-24T03:25:07.207Z","database_specific":{"cna_assigner":"GovTech CSG","cwe_ids":["CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4743.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4743.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4743"},{"type":"FIX","url":"https://github.com/taurusxin/ncmdump/pull/52"},{"type":"PACKAGE","url":"https://github.com/taurusxin/ncmdump"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/taurusxin/ncmdump","events":[{"introduced":"0"},{"fixed":"67cba29a8f09f49c174f2b76143c11d2b1808d82"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.4.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["1.3.2","1.3.1","1.3.0","1.2.1","1.2","1.1","1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4743.json","vanir_signatures_modified":"2026-07-21T23:33:37Z","vanir_signatures":[{"digest":{"line_hashes":["318990695810347547557158514265637926251","9338317173136514254536210925221674528","121183168159056803444733739566655373294","139339287528204286196546398448564969562","122766526917271799239599356515316203179","290983551148902959566366493524173954175","321876008645055741907757985802194360755","250263071470275613700651988968775471451","81183788551116807714838226248875604714","80906137403554564614617979842662216121","196970266893482460497007091506407218159","36058224239406145284537457429276046459"],"threshold":0.9},"id":"CVE-2026-4743-208764a7","signature_type":"Line","signature_version":"v1","source":"https://github.com/taurusxin/ncmdump/commit/67cba29a8f09f49c174f2b76143c11d2b1808d82","target":{"file":"src/ncmcrypt.cpp"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/taurusxin/ncmdump/commit/67cba29a8f09f49c174f2b76143c11d2b1808d82","target":{"file":"src/ncmcrypt.cpp","function":"NeteaseCrypt::NeteaseCrypt"},"deprecated":false,"digest":{"function_hash":"246417510719823758533671842562647060690","length":1980},"id":"CVE-2026-4743-524f142e","signature_type":"Function"},{"target":{"file":"src/main.cpp"},"deprecated":false,"digest":{"line_hashes":["32520141527284375825639705327561794852","92378120953257912515541173991899587814","172827436997446490000696165076657091444","5634679522791739387340997820679724174"],"threshold":0.9},"id":"CVE-2026-4743-87cbf87a","signature_type":"Line","signature_version":"v1","source":"https://github.com/taurusxin/ncmdump/commit/67cba29a8f09f49c174f2b76143c11d2b1808d82"},{"digest":{"function_hash":"268777702313655351223816057604952022586","length":727},"id":"CVE-2026-4743-d816829a","signature_type":"Function","signature_version":"v1","source":"https://github.com/taurusxin/ncmdump/commit/67cba29a8f09f49c174f2b76143c11d2b1808d82","target":{"file":"src/main.cpp","function":"processFile"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:N/R:U/V:D/RE:L/U:Green"}]}