Vulnerability Description
A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The identifier of the patch is 2f45fe860d00990e79e13250251c1dde633f1f89. Applying a patch is the recommended action to fix this issue.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Strlen | Lobster | <= 2025.4 |
Related Weaknesses (CWE)
References
- https://github.com/aardappel/lobster/Product
- https://github.com/aardappel/lobster/commit/2f45fe860d00990e79e13250251c1dde633fPatch
- https://github.com/aardappel/lobster/issues/396PatchVendor AdvisoryIssue Tracking
- https://github.com/aardappel/lobster/issues/396#issuecomment-3849019040PatchVendor AdvisoryIssue Tracking
- https://github.com/oneafter/0204/blob/main/lob2/repro.lobsterExploit
- https://vuldb.com/?ctiid.345006Permissions RequiredVDB Entry
- https://vuldb.com/?id.345006Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.753168ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2026-2259?
CVE-2026-2259 is a vulnerability with a CVSS score of 3.3 (LOW). A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsi...
How severe is CVE-2026-2259?
CVE-2026-2259 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-2259?
Check the references section above for vendor advisories and patch information. Affected products include: Strlen Lobster.