Cstruct indexing bugs can corrupt filtered output and reverse parsing results
Multiple logical indexing and bounds-calculation bugs exist in the cstruct library prior to version 6.3.0. These bugs cause functions like filter_map, tail, cuts, find, and find_sub to produce corrupted output, raise unexpected exceptions, or return data slices outside the intended view. While not direct memory-safety vulnerabilities, these issues can lead to validation bypasses, denial of service, or unintended disclosure of adjacent buffer contents in security-sensitive parsers. A patch fixing these issues was released in cstruct version 6.3.0.
AI Analysis
Technical Summary
Several functions in the cstruct library contain logical indexing and bounds-calculation errors (CWE-682) that cause incorrect data handling. Specifically, Cstruct.filter_map writes retained bytes at original input positions causing corrupted output when bytes are dropped; Cstruct.tail with rev:true removes two bytes instead of one and raises exceptions on single-byte views; Cstruct.cuts with rev:true may split input incorrectly and use offsets outside the requested view; Cstruct.find and Cstruct.find_sub with rev:true may return slices from wrong locations on non-zero-offset views. These bugs do not cause direct memory safety violations but can result in corrupted data, unexpected exceptions, incorrect splits, or disclosure of adjacent buffer contents. The issues were reported in September 2026 and fixed in cstruct version 6.3.0.
Potential Impact
Affected functions may return corrupted data, raise unexpected exceptions, split input incorrectly, or return bytes outside the requested view but still within the backing buffer. In security-sensitive parsing contexts, this can lead to validation bypasses, denial of service, or unintended disclosure of adjacent buffer contents. There are no direct memory safety violations, but the logical errors undermine data integrity and reliability.
Mitigation Recommendations
A patch fixing these issues is available in cstruct version 6.3.0. Users should upgrade to this version to remediate the vulnerabilities. For those unable to upgrade, backporting the source changes from the patch is recommended. There are no configuration-based mitigations since the issues stem from buggy library calls.
Cstruct indexing bugs can corrupt filtered output and reverse parsing results
Description
Multiple logical indexing and bounds-calculation bugs exist in the cstruct library prior to version 6.3.0. These bugs cause functions like filter_map, tail, cuts, find, and find_sub to produce corrupted output, raise unexpected exceptions, or return data slices outside the intended view. While not direct memory-safety vulnerabilities, these issues can lead to validation bypasses, denial of service, or unintended disclosure of adjacent buffer contents in security-sensitive parsers. A patch fixing these issues was released in cstruct version 6.3.0.
CVSS v3.1
Score 7.3high
Affected software
pkg:opam/cstructRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Several functions in the cstruct library contain logical indexing and bounds-calculation errors (CWE-682) that cause incorrect data handling. Specifically, Cstruct.filter_map writes retained bytes at original input positions causing corrupted output when bytes are dropped; Cstruct.tail with rev:true removes two bytes instead of one and raises exceptions on single-byte views; Cstruct.cuts with rev:true may split input incorrectly and use offsets outside the requested view; Cstruct.find and Cstruct.find_sub with rev:true may return slices from wrong locations on non-zero-offset views. These bugs do not cause direct memory safety violations but can result in corrupted data, unexpected exceptions, incorrect splits, or disclosure of adjacent buffer contents. The issues were reported in September 2026 and fixed in cstruct version 6.3.0.
Potential Impact
Affected functions may return corrupted data, raise unexpected exceptions, split input incorrectly, or return bytes outside the requested view but still within the backing buffer. In security-sensitive parsing contexts, this can lead to validation bypasses, denial of service, or unintended disclosure of adjacent buffer contents. There are no direct memory safety violations, but the logical errors undermine data integrity and reliability.
Mitigation Recommendations
A patch fixing these issues is available in cstruct version 6.3.0. Users should upgrade to this version to remediate the vulnerabilities. For those unable to upgrade, backporting the source changes from the patch is recommended. There are no configuration-based mitigations since the issues stem from buggy library calls.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- OSEC-2026-20
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["opam"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Patch Information
Threat ID: 6aa2af57acd9273b4925a2dd
Added to database: 09/10/2026, 13:23:35 UTC
Last enriched: 09/10/2026, 13:26:11 UTC
Last updated: 09/10/2026, 14:25:59 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.