Description
A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 8dbc3419738da066151991fd2bf1d0c85591dea2. It is suggested to install a patch to address this issue.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource exhaustion via memory leak
Action: Apply Patch
AI Analysis

Impact

A memory leak exists in the fb_clear_parser function of flatcc, a library used to parse FlatBuffer data. The flaw allows repeated allocations without corresponding releases, which can cause a process to consume increasing amounts of memory and eventually crash or become unresponsive. The vulnerability is formally identified as CWE-401 and CWE-404.

Affected Systems

The vulnerability affects Dvidelabs flatcc versions up to and including 0.6.3. The flaw can be triggered by supplying crafted input to the parser, and any project that incorporates flatcc to parse data may be impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, combining medium impact with a remote attack vector. The EPSS score is below 1 %, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the exploit has been publicly disclosed and can be used against exposed services that accept external FlatBuffer input.

Generated by OpenCVE AI on September 15, 2026 at 14:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch identified by commit 8dbc3419738da066151991fd2bf1d0c85591dea2 to flatcc.
  • Upgrade flatcc to a version newer than 0.6.3 to include the security fix.
  • If upgrading is not immediately possible, enforce resource limits on processes that use flatcc or add input size checks to mitigate the impact of the memory leak.

Generated by OpenCVE AI on September 15, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 8dbc3419738da066151991fd2bf1d0c85591dea2. It is suggested to install a patch to address this issue.
Title Dvidelabs flatcc semantics.c fb_clear_parser memory leak
First Time appeared Dvidelabs
Dvidelabs flatcc
Weaknesses CWE-401
CWE-404
CPEs cpe:2.3:a:dvidelabs:flatcc:*:*:*:*:*:*:*:*
Vendors & Products Dvidelabs
Dvidelabs flatcc
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dvidelabs Flatcc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T13:59:24.312Z

Reserved: 2026-09-13T13:01:02.810Z

Link: CVE-2026-90784

cve-icon Vulnrichment

Updated: 2026-09-14T13:59:19.864Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:19:30.500

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:20Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-404

    Improper Resource Shutdown or Release