OSV-2026-1027

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/tarantool/OSV-2026-1027.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/OSV-2026-1027
Published
2026-07-05T00:17:39.793478Z
Modified
2026-08-01T12:30:06.079502601Z
Summary
Heap-buffer-overflow in mp_load_float
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=530970666

Crash type: Heap-buffer-overflow WRITE 4
Crash state:
mp_load_float
mp_decode_float
luamp_decode_with_ctx
References

Affected packages

OSS-Fuzz / tarantool

Package

Name
tarantool
Purl
pkg:generic/tarantool

Affected ranges

Affected versions

3.*
3.6.4
3.7.1
3.7.2-entrypoint
3.8.0
3.8.1-entrypoint
3.9.0-entrypoint

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

fixed_range
"62cb643b0083a1346b685818ab89ceb8a3d24766:42d7de284ffb896006e74a51fbd0f62318b813ba"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/tarantool/OSV-2026-1027.yaml"