Skip to main content
Reconnecting to live updates…

Cstruct indexing bugs can corrupt filtered output and reverse parsing results

0
High
Published: 09/10/2026 (09/10/2026, 10:00:00 UTC)
Source: GCVE Database
Product: cstruct

Description

Multiple logical indexing and bounds-calculation bugs exist in the cstruct library prior to version 6.3.0. These bugs cause functions like filter_map, tail, cuts, find, and find_sub to produce corrupted output, raise unexpected exceptions, or return data slices outside the intended view. While not direct memory-safety vulnerabilities, these issues can lead to validation bypasses, denial of service, or unintended disclosure of adjacent buffer contents in security-sensitive parsers. A patch fixing these issues was released in cstruct version 6.3.0.

CVSS v3.1

Score 7.3high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected software

cstruct
pkg:opam/cstruct
Affected versions
<6.3.0<936f1010d3e9914da9c5c8a4739e9278a37e1c3e=0.4.0=0.4.1=0.5.0=0.5.1=0.5.2=0.5.3=0.6.0=0.6.1=0.6.2=0.7.0=0.7.1=0.8.0=0.8.1=1.0.0=1.0.1=1.1.0=1.2.0=1.3.0=1.3.1=1.4.0=1.5.0=1.6.0=1.7.0=1.7.1=1.8.0=1.9.0=2.0.0=2.1.0=2.2.0=2.3.0=2.3.1=2.3.2=2.4.1=3.0.0=3.0.1=3.0.2=3.1.0=3.1.1=3.2.0=3.2.1=3.3.0=3.4.0=3.5.0=3.6.0=3.7.0=4.0.0=5.0.0=5.1.1=5.2.0=6.0.0=6.0.1=6.1.0=6.1.1=6.2.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 13:26:11 UTC

Technical Analysis

Several functions in the cstruct library contain logical indexing and bounds-calculation errors (CWE-682) that cause incorrect data handling. Specifically, Cstruct.filter_map writes retained bytes at original input positions causing corrupted output when bytes are dropped; Cstruct.tail with rev:true removes two bytes instead of one and raises exceptions on single-byte views; Cstruct.cuts with rev:true may split input incorrectly and use offsets outside the requested view; Cstruct.find and Cstruct.find_sub with rev:true may return slices from wrong locations on non-zero-offset views. These bugs do not cause direct memory safety violations but can result in corrupted data, unexpected exceptions, incorrect splits, or disclosure of adjacent buffer contents. The issues were reported in September 2026 and fixed in cstruct version 6.3.0.

Potential Impact

Affected functions may return corrupted data, raise unexpected exceptions, split input incorrectly, or return bytes outside the requested view but still within the backing buffer. In security-sensitive parsing contexts, this can lead to validation bypasses, denial of service, or unintended disclosure of adjacent buffer contents. There are no direct memory safety violations, but the logical errors undermine data integrity and reliability.

Mitigation Recommendations

A patch fixing these issues is available in cstruct version 6.3.0. Users should upgrade to this version to remediate the vulnerabilities. For those unable to upgrade, backporting the source changes from the patch is recommended. There are no configuration-based mitigations since the issues stem from buggy library calls.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
OSEC-2026-20
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["opam"]
Database Specific Severity
null
Cvss Version
3.1

Threat ID: 6aa2af57acd9273b4925a2dd

Added to database: 09/10/2026, 13:23:35 UTC

Last enriched: 09/10/2026, 13:26:11 UTC

Last updated: 09/10/2026, 14:25:59 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses