Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvgm-8rpx-fmg6

Опубликовано: 04 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.8
CVSS3: 5.5

Описание

Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modified cell count value to trigger an index-out-of-bounds panic when querying, causing denial of service in any application that opens untrusted database files.

Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modified cell count value to trigger an index-out-of-bounds panic when querying, causing denial of service in any application that opens untrusted database files.

EPSS

Процентиль: 2%
0.00121
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.5
nvd
17 дней назад

Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modified cell count value to trigger an index-out-of-bounds panic when querying, causing denial of service in any application that opens untrusted database files.

EPSS

Процентиль: 2%
0.00121
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-125