CVE-2026-29079

NameCVE-2026-29079
DescriptionLexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the qualified_name field. That corrupted value is later used as a pointer and dereferenced near the zero page. This vulnerability is fixed in 2.7.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1130747

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lexbor (PTS)forky, sid2.6.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lexborsource(unstable)(unfixed)1130747

Notes

https://github.com/lexbor/lexbor/security/advisories/GHSA-mrpr-v36q-2vp8

Search for package or bug name: Reporting problems