Quickjs Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    0
    Critical Level Threats
    9
    High Level Threats
    5
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-69654

    A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` interpreter using the `-m` option and a low memory limit can cause an out-of-memory condition followed by an assertion failure in JS_FreeRuntime (list_empty(&rt->gc_obj_list)) during runtime cleanup. Although the engine reports an OOM error, it subsequently aborts with SIGABRT because the GC object list is not fully released. This results in a denial of service.

    Last Modified: Jun 02, 2026
    Published: Mar 06, 2026

    CVE-2025-69653

    A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6 (2025-12-11), in file gc_decref_child in quickjs.c, when executed with the qjs interpreter using the -m option. This leads to an abort (SIGABRT) during garbage collection and causes a denial-of-service.

    Last Modified: Jun 02, 2026
    Published: Mar 06, 2026

    CVE-2025-62496

    Integer overflow in js_bigint_from_string in QuickJS

    Last Modified: Oct 28, 2025
    Published: Oct 16, 2025

    CVE-2025-62495

    Type confusion in string addition in QuickJS

    Last Modified: Oct 29, 2025
    Published: Oct 16, 2025

    CVE-2025-62494

    Type confusion in string addition in QuickJS

    Last Modified: Oct 29, 2025
    Published: Oct 16, 2025
    Items Per Page