jerryscript · Issues· 246 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #5301
[Bug]Snapshot deserialization lacks bounds checks on untrusted offset/length fields -> out-of-bounds read (SEGV / ASan use-after-poison / DoS) (CWE-125)
Updated Sep 11, 2026 - #5302
[Bug]Malformed snapshot bytecode drives VM-init stack-buffer-overflow (vm_init_exec, vm.c:5190) (CWE-125)
Updated Sep 11, 2026 - #5303
[Bug]ecma_make_number_value casts out-of-range double to integer -> UBSan float-cast-overflow (SIGILL) (CWE-681)
Updated Sep 11, 2026 - #5304
[Bug]lexer_construct_number_object casts oversized numeric literal to int32 -> UBSan float-cast-overflow (SIGILL) (CWE-681)
Updated Sep 11, 2026 - #5298
Unusual Multithreading API
Updated Sep 8, 2026 - #5300
Ungraceful handling of stack overflow
Updated Jul 18, 2026 - #5297
JerryScript: Proxy getOwnPropertyDescriptor invariant check misses descriptor defaults
Updated Jun 20, 2026 - #5296
JerryScript: Proxy deleteProperty invariant checks can raise two exceptions and abort debug builds
Updated Jun 20, 2026 - #5295
JerryScript: malformed snapshot literal offset causes out-of-bounds read in ecma_snapshot_get_literal
Updated Jun 20, 2026 - #5294
JerryScript: configurable module namespace re-export causes type confusion and crash
Updated Jun 20, 2026 - #5293
jerryscript jerry-snapshot tool: unbounded literals-list parser → global-buffer-overflow (OOB write) in process_generate
Updated Jun 20, 2026 - #5292
jerryscript: NULL-pointer dereference in ES-module linker (ecma_module_resolve_import) via duplicate var/namespace-import binding — pre-link crash
Updated Jun 20, 2026 - #5291
Private security contact for multiple snapshot loader memory corruption issues
Updated Jun 17, 2026 - #5290
Segmentation fault on self-referential array raised to power of zero
Updated Jun 9, 2026 - #5289
Simple non fixed size jerry_string_to_buffer alternative?
Updated Jun 3, 2026