VendorsBellardquickjsall versions
Vulnerabilities

Bellard Quickjs

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-46687
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Published 2025-04-27 · Analyzed
7.8EPSS 0.003
CVE-2025-12745
QuickJS quickjs.c js_array_buffer_slice buffer over-read
Published 2025-11-05 · Analyzed
7.8EPSS 0.002
CVE-2024-33263
QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.
Published 2024-04-26 · Analyzed
4.0EPSS 0.003