VDB
CVE-2026-42046
CVE-2026-42046
PUBLISHED
CVSS 7.8 HIGH
Reported by GitHub_M · Published May 11, 2026
libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a crafted file in the "caca" format. Depending on the build configuration and memory allocator, this may lead to memory corruption or remote code execution. This is the same vulnerability as CVE-2021-3410 but the fix at that time was not fully correct. Commit fb77acff9ba6bb01d53940da34fb10f20b156a23 fixes this vulnerability.
EPSS 0.22% · 13.2th percentile
Risk Scores
CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.22%
13.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cacalabs | libcaca | <= 0.99.beta20 |
| cacalabs | libcaca | <= 0.99.beta20 |
Timeline
- May 11, 2026 CVE Published
- May 12, 2026 CVE Updated
- May 15, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
References
- https://github.com/cacalabs/libcaca/security/advisories/GHSA-4vvg-vrqv-m56w x_refsource_CONFIRM
- https://github.com/cacalabs/libcaca/issues/86 x_refsource_MISC
- https://github.com/cacalabs/libcaca/commit/fb77acff9ba6bb01d53940da34fb10f20b156a23 x_refsource_MISC