CVE-2020-15888: Lua

High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.

Affected products

  • Lua Lua: version 5.4.0 only

Published 2020-07-21. Last modified 2026-06-17.