VendorsQuickJS Projectquickjsall versions
Vulnerabilities

QuickJS Project QuickJS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2025-62494
Type confusion in string addition in QuickJS
Published 2025-10-16 · Analyzed
8.8EPSS 0.005
CVE-2025-62496
Integer overflow in js_bigint_from_string in QuickJS
Published 2025-10-16 · Analyzed
8.8EPSS 0.005
CVE-2025-62495
Type confusion in string addition in QuickJS
Published 2025-10-16 · Analyzed
8.8EPSS 0.005
CVE-2025-62490
Use-after-free in js_print_object in QuickJS
Published 2025-10-16 · Analyzed
8.8EPSS 0.004
CVE-2025-62491
Use-after-free in js_std_promise_rejection_check in QuickJS
Published 2025-10-16 · Analyzed
8.8EPSS 0.004
CVE-2025-46688
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Published 2025-04-27 · Analyzed
8.4EPSS 0.003
CVE-2020-22876
Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is resolved in the 2020-07-05 release.
Published 2021-07-13 · Modified
7.5EPSS 0.016
CVE-2023-31922
QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
Published 2023-05-12 · Modified
7.5EPSS 0.007
CVE-2023-48183
QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.
Published 2024-04-23 · Analyzed
7.5EPSS 0.006
CVE-2025-69654
A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` interpreter using the `-m` option and a low memory limit can cause an out-of-memory condition followed by an assertion failure in JS_FreeRuntime (list_empty(&rt->gc_obj_list)) during runtime cleanup. Although the engine reports an OOM error, it subsequently aborts with SIGABRT because the GC object list is not fully released. This results in a denial of service.
Published 2026-03-06 · Analyzed
7.5EPSS 0.003
CVE-2025-62492
Heap out-of-bounds read in js_typed_array_indexOf in QuickJS
Published 2025-10-16 · Analyzed
6.5EPSS 0.004
CVE-2025-62493
Heap out-of-bounds read in js_bigint_to_string1 in QuickJS
Published 2025-10-16 · Analyzed
6.5EPSS 0.004
CVE-2025-69653
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6 (2025-12-11), in file gc_decref_child in quickjs.c, when executed with the qjs interpreter using the -m option. This leads to an abort (SIGABRT) during garbage collection and causes a denial-of-service.
Published 2026-03-06 · Analyzed
6.5EPSS 0.002
CVE-2023-48184
QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures.
Published 2024-04-23 · Analyzed
3.9EPSS 0.003