VDB

CVE-2026-1144

CVE-2026-1144 PUBLISHED CVSS 5.300000190734863 MEDIUM

A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.

EPSS 0.36% · 28.4th percentile

Risk Scores

CVSS 4.0
5.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS Score
0.36%
28.4th percentile

Affected Products

VendorProductVersions
quickjs-ngquickjs0.1, 0.2, 0.4

Timeline

  • Jan 6, 2026 Fix PR Merged
  • Jan 19, 2026 EPSS Score
  • Jan 19, 2026 CVE Published
  • Jan 19, 2026 PoC Published
  • Jan 22, 2026 EPSS Score
  • Jan 25, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 30, 2026 PoC Published
  • Jan 31, 2026 EPSS Score
  • Feb 3, 2026 EPSS Score
  • Feb 6, 2026 EPSS Score
  • Feb 7, 2026 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›