Vulnerability Description
Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the qualified_name field. That corrupted value is later used as a pointer and dereferenced near the zero page. This vulnerability is fixed in 2.7.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lexbor | Lexbor | < 2.7.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-29079?
CVE-2026-29079 is a vulnerability with a CVSS score of 7.5 (HIGH). Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constr...
How severe is CVE-2026-29079?
CVE-2026-29079 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29079?
Check the references section above for vendor advisories and patch information. Affected products include: Lexbor Lexbor.