CVE Explorer
CVE-2026-1188
In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly sized, failing to account for the separator when determining when a write to the buffer was safe could lead to a buffer overflow. This issue is fixed in Eclipse OMR version 0.8.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Eclipse OMR","repo":"https://github.com/eclipse-omr/omr","vendor":"Eclipse Foundation","versions":[{"lessThan":"0.8.0","status":"affected","version":"0.2.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e7f45fa9711bda1a8532fc16e8e846eab96b410408e0a2b32fdbf40fec1da477 · sha256:8575109123091905… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"LO…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e7f45fa9711bda1a8532fc16e8e846eab96b410408e0a2b32fdbf40fec1da477 · sha256:8575109123091905… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-131","description":"CWE-131 Incorrect Calculation of Buffer Size","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e7f45fa9711bda1a8532fc16e8e846eab96b410408e0a2b32fdbf40fec1da477 · sha256:8575109123091905… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://github.com/eclipse-omr/omr/pull/8082"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e7f45fa9711bda1a8532fc16e8e846eab96b410408e0a2b32fdbf40fec1da477 · sha256:8575109123091905… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.