LOW
Lua segfault in unpack()
Published Feb 3, 2026
1.7
LOWCVSS 4.0
EPSS 0.33%
Description
Vulnerability in Wikimedia Foundation Scribunto, Wikimedia Foundation luasandbox. This vulnerability is associated with program files includes/Engines/LuaCommon/lualib/mwInit.Lua, library.C.
This issue affects Scribunto: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1; luasandbox: from * before fea2304f8f6ab30314369a612f4f5b165e68e95a.
Affected products
-
- Version -StatusaffectedConstraints<1.39.16, 1.43.6, 1.44.3, 1.45.1
- Version
-
- Version -StatusaffectedConstraints
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Wikimedia Foundation | Scribunto | unaffected |
| ||||||
| Wikimedia Foundation | Luasandbox | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (1)
| Link | Providers | Tags |
|---|---|---|
| https://phabricator.wikimedia.org/T408135 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner wikimedia-foundation
Published Feb 3, 2026
Updated Mar 2, 2026
Reserved Dec 8, 2025
Link CVE-2025-67482
CISA Vulnrichment
Updated Feb 3, 2026