Skip to main content

Security update for tree-sitter

0
High
Published: 05/14/2026 (05/14/2026, 08:07:53 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for tree-sitter fixes the following issues Security issues: - CVE-2026-34941: wasmtime: crafted input string can lead to an out-of-bound read (bsc#1261871). - CVE-2026-34942: wasmtime: unaligned pointers can lead to a denial of service (bsc#1261894). - CVE-2026-34943: wasmtime: lifting `flags` component value can lead to a denial of service (bsc#1261954). - CVE-2026-34944: wasmtime: out-of-bounds read during WebAssembly compilation can lead to a denial of service (bsc#1261963). - CVE-2026-34945: wasmtime: incorrectly translated table.size could lead to disclosing data (bsc#1262007). - CVE-2026-34946: wasmtime: denial of service due to WebAssembly compilation error (bsc#1261974). - CVE-2026-34987: wasmtime: winch compiler backend may allow a sandbox-escaping memory access (bsc#1262032). - CVE-2026-34988: wasmtime: pooling allocator instances can cause data leakage (bsc#1261968). - CVE-2026-35186: wasmtime: translating the table.grow operator can cause a masked return value (bsc#1262036). - CVE-2026-35195: wasmtime: transcoding strings can lead to an out of bound write or a crash (bsc#1262040). Changes for tree-sitter: - update to 0.26.8: * fix(generate): allow disabling qjs-rt feature from CLI by @WillLillis in #5448 * fix(lib): document invariants that must be upheld for TSInputEdit by @WillLillis in #5452 * fix(cli): correct typo in parse command's help text by @WillLillis in #5465 * perf(cli): misc. improvements by @tree-sitter-ci-bot[bot] in #5476 * Fix wasm loading of languages w/ multiple reserved word sets by @tree-sitter-ci-bot[bot] in #5477 * generate: avoid panicking when a supertype only has hidden external token children by @tree-sitter-ci-bot[bot] in #5478

Affected software

Affected versions
SUSEaarch64libtree-sitter0_26-0.26.8-160000.1.1.aarch64tree-sitter-0.26.8-160000.1.1.aarch64tree-sitter-devel-0.26.8-160000.1.1.aarch64

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
openSUSE-SU-2026:20749-1
Cve Count
10
Additional Cves
["CVE-2026-34942","CVE-2026-34943","CVE-2026-34944","CVE-2026-34945","CVE-2026-34946","CVE-2026-34987","CVE-2026-34988","CVE-2026-35186","CVE-2026-35195"]
State
PUBLISHED

Threat ID: 6aab498455bf5e2cf5990ee3

Added to database: 09/17/2026, 01:59:32 UTC

Last updated: 09/17/2026, 02:02:25 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses