VendorsQuickJS-NGquickjsall versions
Vulnerabilities

QuickJS-NG QuickJS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-0821
quickjs-ng quickjs quickjs.c js_typed_array_constructor heap-based overflow
Published 2026-01-10 · Modified
9.8EPSS 0.005
CVE-2026-0822
quickjs-ng quickjs quickjs.c js_typed_array_sort heap-based overflow
Published 2026-01-10 · Modified
8.8EPSS 0.005
CVE-2026-1144
quickjs-ng quickjs Atomics Ops quickjs.c use after free
Published 2026-01-19 · Modified
8.8EPSS 0.004
CVE-2026-1145
quickjs-ng quickjs quickjs.c js_typed_array_constructor_ta heap-based overflow
Published 2026-01-19 · Modified
8.8EPSS 0.004
CVE-2025-46688
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Published 2025-04-27 · Analyzed
8.4EPSS 0.003
CVE-2025-46687
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Published 2025-04-27 · Analyzed
7.8EPSS 0.003
CVE-2024-13903
quickjs-ng QuickJS qjs quickjs.c JS_GetRuntime stack-based overflow
Published 2025-03-21 · Analyzed
7.5EPSS 0.007