{"id":"CVE-2026-88355","details":"An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function allocates less memory than sizeof(te_expr) but treats the returned allocation as a complete te_expr object. This results in undefined behavior and can cause deterministic process termination in UBSan-instrumented builds.","modified":"2026-09-26T08:05:08.127164Z","published":"2026-09-24T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88355.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88355.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88355"},{"type":"REPORT","url":"https://github.com/codeplea/tinyexpr/issues/145"},{"type":"FIX","url":"https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/szaydel/tinyexpr","events":[{"introduced":"0"},{"fixed":"fe7459728c2ab8d2f91365abe56601cdd0e24f9b"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88355.json","vanir_signatures_modified":"2026-09-26T08:05:08Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b","target":{"file":"tinyexpr.c"},"deprecated":false,"digest":{"line_hashes":["328501302803661730252761329592220338325","30229056534046461085818270848024266989","3107057848197806472077546343778336183","241973780648151657723568189387079775361"],"threshold":0.9},"id":"CVE-2026-88355-0dda26d9","signature_type":"Line"},{"target":{"file":"tinyexpr.c","function":"new_expr"},"deprecated":false,"digest":{"function_hash":"9847663013638542663353395907742480339","length":479},"id":"CVE-2026-88355-b0d34760","signature_type":"Function","signature_version":"v1","source":"https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b"},{"deprecated":false,"digest":{"line_hashes":["52760609968046561809843419364735674836","240354706997081154450127997360094328769","318978910677225100876928235940698025718","143645653040372076205694005715644119143"],"threshold":0.9},"id":"CVE-2026-88355-cdf148b7","signature_type":"Line","signature_version":"v1","source":"https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b","target":{"file":"tinyexpr.h"}}]}}],"schema_version":"1.9.0"}