CVE-2020-15888: Lua
High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
Affected products
- Lua Lua: version 5.4.0 only
Published 2020-07-21. Last modified 2026-06-17.