CVE-2026-10267: Janet-Lang Janet

Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/core/debug.c. Performing a manipulation results in out-of-bounds read. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named ed17dd2c5913a23fb1107251e44a9410a3c30cf5.

Affected products

  • Janet-Lang Janet: version 1.0 only; version 1.1 only; version 1.2 only; version 1.3 only; version 1.4 only; version 1.5 only; …

Published 2026-06-01. Last modified 2026-07-22.