PT-2026-30709 · Unknown · Openfpgaloader

·

CVE-2026-35170

·

Published

2026-04-06

·

Updated

2026-07-20

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions openFPGALoader versions 1.1.1 and earlier
Description openFPGALoader is a utility for programming FPGAs. A heap-buffer-overflow read vulnerability exists in the BitParser::parseHeader() function when parsing a crafted .bit file, allowing out-of-bounds heap memory access. No FPGA hardware is required to trigger this issue.
Recommendations Update to a version later than 1.1.1.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35170
GHSA-V59X-FVPJ-J22X

Affected Products

Openfpgaloader