CVE-2026-108063
Received Received - Intake

libhangul Hanja Dictionary Parsing Denial of Service

Vulnerability report for CVE-2026-108063, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: redhat-SADP

Description

A flaw was found in libhangul. When parsing Hanja dictionary files, the library fails to verify that an entry contains a valid value alongside its key. By providing a specially crafted dictionary file to an application that queries it, an attacker can trigger an unexpected application crash, resulting in a Denial of Service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
libhangul libhangul *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in libhangul, a library used for processing Hangul (Korean) text. When parsing Hanja dictionary files, the library does not validate that entries contain valid values alongside their keys. An attacker can exploit this by providing a maliciously crafted dictionary file to an application using libhangul, causing the application to crash and resulting in a Denial of Service (DoS).

Detection Guidance

This vulnerability can be detected by checking for crashes in applications using libhangul when processing Hanja dictionary files. Monitor application logs for unexpected terminations or segmentation faults during dictionary parsing.

Impact Analysis

If you use an application that relies on libhangul for processing Hanja dictionary files, an attacker could exploit this vulnerability to crash the application. This could disrupt services or functionality that depend on the library, leading to downtime or loss of access to critical features.

Compliance Impact

This vulnerability primarily causes Denial of Service (DoS) via application crashes, which may impact availability of systems processing Korean text. For GDPR, availability is a key principle, so repeated crashes could affect compliance with data access requirements. HIPAA requires availability of protected health information systems; crashes could disrupt access to critical data. However, the vulnerability does not directly impact confidentiality or integrity of data.

Mitigation Strategies

Update libhangul to the latest patched version. Avoid using untrusted Hanja dictionary files. Implement input validation for dictionary files in applications using libhangul.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108063. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart