CVE-2026-1145 | quickjs-ng quickjs up to 0.11.0 quickjs.c js_typed_array_constructor_ta heap-based overflow (Issue 1305)
A vulnerability marked as critical has been reported in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow.
This vulnerability is tracked as CVE-2026-1145. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is suggested to install a patch to address this issue.