CVE-2026-86315

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX. This issue affects Escargot: 5dc93606abd42b859045add05d704a038e197359.

  • Published Sep 7, 2026
  • CVSS 6.2 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86315 at the National Vulnerability Database