CVE-2025-26519: Musl-Libc Musl

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusted EUC-KR text to UTF-8.

Affected products

  • Musl-Libc Musl: from 0.9.13, before 1.2.6 (fixed in 1.2.6)

Published 2025-02-14. Last modified 2026-06-17.