---
id: CVE-2026-90784
title: A vulnerability has been found in Dvidelabs flatcc up to 0.6.3
summary: >-
  A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted
  element is the function fb_clear_parser of the file src/Compiler/semantics.c.
  The manipulation leads to memory leak. It is possible to initiate the attack
  remot…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-401
  - CWE-404
vendor: Dvidelabs
product: flatcc
affected:
  - flatcc 0.6.0
  - flatcc 0.6.1
  - flatcc 0.6.2
  - flatcc 0.6.3
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:56:48.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90784'
references:
  - url: 'https://github.com/dvidelabs/flatcc/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/dvidelabs/flatcc/commit/8dbc3419738da066151991fd2bf1d0c85591dea2
    label: cna@vuldb.com
  - url: 'https://github.com/dvidelabs/flatcc/issues/389'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90784'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/919199'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403290'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403290/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T13:59:14.010514Z'
ingestedAt: '2026-09-14T15:23:07.421Z'
epss: 0.00419
epssPercentile: 0.35839
---

## Overview

A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 8dbc3419738da066151991fd2bf1d0c85591dea2. It is suggested to install a patch to address this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
