Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/bellard/quickjs/issues/468 |
|
Thu, 12 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bellard
Bellard quickjs |
|
| Vendors & Products |
Bellard
Bellard quickjs |
Fri, 06 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` interpreter using the `-m` option and a low memory limit can cause an out-of-memory condition followed by an assertion failure in JS_FreeRuntime (list_empty(&rt->gc_obj_list)) during runtime cleanup. Although the engine reports an OOM error, it subsequently aborts with SIGABRT because the GC object list is not fully released. This results in a denial of service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-12T18:39:37.202Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69654
Updated: 2026-03-12T18:39:30.234Z
Status : Awaiting Analysis
Published: 2026-03-06T20:16:11.900
Modified: 2026-03-12T19:16:15.413
Link: CVE-2025-69654
No data.
OpenCVE Enrichment
Updated: 2026-03-09T10:08:30Z