VDB
CVE-2026-1144
CVE-2026-1144
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.
EPSS 0.36% · 28.4th percentile
Risk Scores
CVSS 4.0
5.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS Score
0.36%
28.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| quickjs-ng | quickjs | 0.1, 0.2, 0.4 |
Timeline
- Jan 6, 2026 Fix PR Merged
- Jan 19, 2026 EPSS Score
- Jan 19, 2026 CVE Published
- Jan 19, 2026 PoC Published
- Jan 22, 2026 EPSS Score
- Jan 25, 2026 EPSS Score
- Jan 28, 2026 EPSS Score
- Jan 30, 2026 PoC Published
- Jan 31, 2026 EPSS Score
- Feb 3, 2026 EPSS Score
- Feb 6, 2026 EPSS Score
- Feb 7, 2026 PoC Published
References
- https://github.com/quickjs-ng/quickjs/issues/1301 discussion
- https://github.com/quickjs-ng/quickjs/pull/1303 fix
- https://github.com/quickjs-ng/quickjs/issues/1302 discussion
- https://github.com/quickjs-ng/quickjs/commit/ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141 fix
- VDB-341737 | quickjs-ng quickjs Atomics Ops quickjs.c use after free vdb
- VDB-341737 | CTI Indicators (IOB, IOC, IOA) url
- Submit #735538 | quickjs-ng quickjs v0.11.0 Use After Free (Duplicate) third-party-advisory
- https://github.com/quickjs-ng/quickjs/ technical
- https://vuldb.com/?submit.735537 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-1144 advisory
- https://github.com/quickjs-ng/quickjs url