Description
A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/compiler/semantics.c of the component Struct Analysis. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit has been made public and could be used. The patch is identified as f705032346ee39efd7d3848c50b73d455d28d06d. A patch should be applied to remediate this issue.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Exploit via Assertion
Action: Apply Patch
AI Analysis

Impact

The flaw is a reachable assertion (CWE-617) that can be triggered in the analyze_struct function of flatcc’s compiler component. Triggering the assertion can cause the compiler to fail, and the issue permits a remote attack with publicly available exploits.

Affected Systems

The vulnerability affects Dvidelabs flatcc versions up to and including 0.6.3. The issue is located in src/compiler/semantics.c of the Struct Analysis component.

Risk and Exploitability

CVSS 6.9 denotes moderate severity, and the EPSS score is not available, making exploitation likelihood uncertain. The vulnerability is not listed in the CISA KEV catalog. Attack requires remote access to the compiler environment, and the public proof‑of‑concept demonstrates that the exploit is publicly available. Because the flaw is an assertion, it may result in a a crash is not indicated by the current description.

Generated by OpenCVE AI on September 15, 2026 at 13:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch identified by commit f705032346ee39efd7d3848c50b73d455d28d06d to flatcc or upgrade to a version newer than 0.6.3 that includes the fix
  • Recompile flatcc after applying the patch to ensure the vulnerable code is replaced
  • If the patch cannot be applied immediately, reconfigure your build process to avoid invoking the analyze_struct component until the vulnerability is fixed

Generated by OpenCVE AI on September 15, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/compiler/semantics.c of the component Struct Analysis. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit has been made public and could be used. The patch is identified as f705032346ee39efd7d3848c50b73d455d28d06d. A patch should be applied to remediate this issue.
Title Dvidelabs flatcc Struct Analysis semantics.c analyze_struct assertion
First Time appeared Dvidelabs
Dvidelabs flatcc
Weaknesses CWE-617
CPEs cpe:2.3:a:dvidelabs:flatcc:*:*:*:*:*:*:*:*
Vendors & Products Dvidelabs
Dvidelabs flatcc
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dvidelabs Flatcc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:57:11.101Z

Reserved: 2026-09-13T13:01:10.577Z

Link: CVE-2026-90785

cve-icon Vulnrichment

Updated: 2026-09-15T13:47:23.295Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:19.183

Modified: 2026-09-15T14:17:34.570

Link: CVE-2026-90785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:16Z

Weaknesses