CVE-2026-3407: Yosyshq Yosys

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Applying a patch is the recommended action to fix this issue. It appears that the issue is not reproducible all the time.

Affected products

  • Yosyshq Yosys: version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; version 0.5 only; version 0.6 only; …

Published 2026-03-02. Last modified 2026-06-17.