Low severity3.3NVD Advisory· Published Feb 27, 2026· Updated Jun 17, 2026
CVE-2026-3285
CVE-2026-3285
Description
A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the file src/be_lexer.c. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: 7149c59a39ba44feca261b12f06089f265fec176. Applying a patch is the recommended action to fix this issue.
Affected products
3cpe:2.3:a:berry-lang:berry:1.1.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:berry-lang:berry:1.1.0:*:*:*:*:*:*:*
- (no CPE)range: <=1.1.0
- (no CPE)range: 1.0
Patches
Vulnerability mechanics
References
7- github.com/berry-lang/berry/commit/7149c59a39ba44feca261b12f06089f265fec176nvdPatch
- github.com/berry-lang/berry/issues/509nvdExploitIssue Tracking
- github.com/oneafter/0211/blob/main/be/repronvdExploit
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- github.com/berry-lang/berry/pull/511nvdIssue Tracking
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.