CVE-2025-46688

quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:quickjs-ng:quickjs:*:*:*:*:*:*:*:*
cpe:2.3:a:quickjs_project:quickjs:*:*:*:*:*:*:*:*

History

30 May 2025, 16:29

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-27 20:15

Updated : 2025-05-30 16:29


NVD link : CVE-2025-46688

Mitre link : CVE-2025-46688

CVE.ORG link : CVE-2025-46688


JSON object : View

Products Affected

quickjs_project

  • quickjs

quickjs-ng

  • quickjs
CWE
CWE-131

Incorrect Calculation of Buffer Size