VYPR

bison

by Debian

CVEs (2)

  • CVE-2026-56390Jul 30, 2026
    risk 0.00cvss epss

    GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this…

  • CVE-2026-56389Jul 30, 2026
    risk 0.00cvss epss

    GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc,…