CVE-2024-25176: Luajit

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.

Affected products

  • Luajit Luajit: up to and including 2.1.0

Published 2025-07-07. Last modified 2026-06-17.