CVE-2026-62866 | TomWright dasel up to 3.11.1 Lexer tokenize.go parseCurRune out-of-bounds

SecurityVulns

A vulnerability was found in TomWright dasel up to 3.11.1. It has been declared as problematic. Affected is the function parseCurRune of the file selector/lexer/tokenize.go of the component Lexer. Such manipulation leads to out-of-bounds read.

This vulnerability is documented as CVE-2026-62866. The attack needs to be performed locally. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More