CVE-2026-1188 — Incorrect Calculation of Buffer Size in Foundation Eclipse OMR
CWE-131 — Incorrect Calculation of Buffer SizeCWE-120 — Classic Buffer OverflowCWE-1188 — Initialization of a Resource with an Insecure DefaultCWE-918 — Server-Side Request ForgeryCWE-306 — Missing Authentication for Critical FunctionCWE-749 — Exposed Dangerous Method or FunctionCWE-668 — Resource ExposureCWE-276 — Incorrect Default PermissionsCWE-321 — Use of Hard-coded Cryptographic KeyCWE-22 — Path TraversalCWE-287 — Improper AuthenticationCWE-78 — OS Command Injection14 documents7 sources
Severity
6.9MEDIUMNVD
GHSA9.8
EPSS
0.0%
top 94.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 29
Latest updateApr 8
Description
In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly sized, failing to account for the separator when determining when a write to the buffer was safe could lead to a buffer overflow. This issue is fixed in Eclipse OMR version 0.8.0.
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L