CVE-2023-46046
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to process a series of atttacker-controlled .mzn files.
Published 2024-03-27. Last modified 2026-06-17.