CVE-2026-58303
Deferred Deferred - Pending Action

Stack-based Buffer Overflow in Samsung Open Source Escargot

Vulnerability report for CVE-2026-58303, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-09

Last updated on: 2026-07-09

Assigner: Samsung TV & Appliance

Description

Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-09
Last Modified
2026-07-09
Generated
2026-07-15
AI Q&A
2026-07-09
EPSS Evaluated
2026-07-14
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
samsung escargot to b30b63fc63b403907d8137da1c65aaa4521fe74e (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Compliance Impact

The provided information does not include any details on how the vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.

Executive Summary

CVE-2026-58303 is a stack-based buffer overflow vulnerability in the Samsung Open Source Escargot JavaScript engine. This vulnerability allows overflow buffers, which can lead to memory corruption.

Impact Analysis

The vulnerability has a CVSS v3.1 base score of 6.1, indicating a medium severity. It requires local access (AV:L) with low attack complexity (AC:L) and no privileges (PR:N), but user interaction is required (UI:R). The impact on confidentiality is none (C:N), but it can cause integrity loss (I:L) and high availability impact (A:H). This means an attacker with local access and user interaction could exploit the buffer overflow to cause crashes or potentially execute arbitrary code, leading to denial of service or other integrity issues.

Mitigation Strategies

To mitigate the vulnerability CVE-2026-58303 in Samsung Open Source Escargot, you should update Escargot to a version that includes the fixes described in the patch addressing labeled continue and break statement issues, crashes, and environment cleanup problems.

Specifically, ensure your Escargot version is at or beyond commit b30b63fc63b403907d8137da1c65aaa4521fe74e, as versions before this are affected.

Applying the patch from the pull request that fixes these issues will prevent crashes and incorrect behavior related to labeled loops and environment handling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58303. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart