CVE-2026-58307 Details
Description
Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.
A vulnerability in Samsung Open Source Escargot prior to commit 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c allows for an out-of-bounds read. This reachable assertion vulnerability can lead to buffer overreads and manipulation of input data. The issue arises from improper handling of certain values, which can be exploited to read beyond the allocated memory bounds, potentially leading to information leakage or other unintended behavior.
The vulnerability has been addressed in a pull request that is available for review.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Samsung/escargot/issues/1577 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Samsung/escargot/issues/1577 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Samsung/escargot/pull/1586 | [email protected] | Issue TrackingVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Samsung Escargot | < 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion