MEDIUM
janet-lang janet specials.c janetc_if out-of-bounds
Published Feb 9, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.17%
Description
A vulnerability was determined in janet-lang janet up to 1.40.1. This impacts the function janetc_if of the file src/core/specials.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called c43e06672cd9dacf2122c99f362120a17c34b391. It is advisable to implement a patch to correct this issue.
Affected products
-
- Version 1.40.0StatusaffectedConstraints-
- Version 1.40.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Janet-Lang | Janet | n/a |
|
- ≤ 1.40.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://github.com/janet-lang/janet/ product
- https://github.com/janet-lang/janet/commit/c43e06672cd9dacf2122c99f362120a17c34b391 patch
- https://github.com/janet-lang/janet/issues/1700 issue-trackingExploitIssue Tracking
- https://github.com/janet-lang/janet/issues/1702 issue-trackingExploitIssue Tracking
- https://github.com/oneafter/0123/blob/main/ja2/repro exploit
- https://vuldb.com/?ctiid.344981 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.344981 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.754495 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://github.com/janet-lang/janet/ | product | |
| https://github.com/janet-lang/janet/commit/c43e06672cd9dacf2122c99f362120a17c34b391 | patch | |
| https://github.com/janet-lang/janet/issues/1700 | issue-trackingExploitIssue Tracking | |
| https://github.com/janet-lang/janet/issues/1702 | issue-trackingExploitIssue Tracking | |
| https://github.com/oneafter/0123/blob/main/ja2/repro | exploit | |
| https://vuldb.com/?ctiid.344981 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.344981 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.754495 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Feb 9, 2026
Updated Feb 23, 2026
Reserved Feb 9, 2026
Link CVE-2026-2242
CISA Vulnrichment
Updated Feb 9, 2026