---
id: CVE-2026-92259
title: >-
  Integer overflow or wraparound vulnerability in Samsung Opensource Escargot
  allows attackers with write access to the bytecode-cache directory to cause a
  heap-based buffer overflow and denial of service via a crafted cache file.


  This is…
summary: >-
  Integer overflow or wraparound vulnerability in Samsung Opensource Escargot
  allows attackers with write access to the bytecode-cache directory to cause a
  heap-based buffer overflow and denial of service via a crafted cache file.


  This is…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-190
vendor: Samsung Opensource
product: Escargot
affected:
  - Escargot ac94df78493ee6fede286620d94f724e46b4d238
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:29:56.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92259'
references:
  - url: 'https://github.com/Samsung/escargot/pull/1650'
    label: PSIRT@samsung.com
tags:
  - nvd
  - cve.org
epss: 0.0014
epssPercentile: 0.02714
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T18:06:55.309594Z'
ingestedAt: '2026-09-15T21:44:50.656Z'
---

## Overview

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file.

This issue affects Escargot: ac94df78493ee6fede286620d94f724e46b4d238.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
