CVE-2026-29079

Name
CVE-2026-29079
Description
Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the qualified_name field. That corrupted value is later used as a pointer and dereferenced near the zero page. This vulnerability is fixed in 2.7.0.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/lexbor/lexbor/security/advisories/GHSA-mrpr-v36q-2vp8

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:lexbor:lexbor:*:*:*:*:*:*:*:* lexbor >= None < 2.7.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
php85 edge-community 8.5.6-r0 Andy Postnikov <apostnikov@gmail.com> fixed
php85 3.23-community 8.5.6-r0 Andy Postnikov <apostnikov@gmail.com> fixed
php84 3.23-community 8.4.21-r0 Andy Postnikov <apostnikov@gmail.com> fixed
lexbor edge-community 2.6.0-r0 Haelwenn (lanodan) Monnier <contact+alpine@hacktivis.me> possibly vulnerable
lexbor edge-community 2.5.0-r0 Haelwenn (lanodan) Monnier <contact+alpine@hacktivis.me> possibly vulnerable
lexbor edge-community 2.4.0-r0 Haelwenn (lanodan) Monnier <contact+alpine@hacktivis.me> possibly vulnerable
lexbor 3.23-community 2.6.0-r0 Haelwenn (lanodan) Monnier <contact+alpine@hacktivis.me> possibly vulnerable