CVE-2026-2240: Janet-Lang Janet
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef of the file src/core/compile.c. Such manipulation leads to out-of-bounds read. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The name of the patch is 4dd08a4cdef5b1c42d9a2c19fc24412e97ef51d5. A patch should be applied to remediate this issue.
Affected products
- Janet-Lang Janet: up to and including 1.40.1
Published 2026-02-09. Last modified 2026-06-17.