CVE-2026-18852 | epsilla-cloud vectordb Filter Parser expr.cpp SplitTokens/ShuntingYard unusual condition

SecurityVulns

A vulnerability, which was classified as problematic, was found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to improper check for unusual conditions.

This vulnerability is documented as CVE-2026-18852. The attack needs to be performed locally. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More