PT-2026-53863 · Fzf · Fzf

·

CVE-2026-53432

·

Published

2026-06-30

·

Updated

2026-06-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions fzf versions prior to 0.73.1
Description An integer overflow occurs in the FuzzyMatchV2() function when the input line length is approximately 2,200,000 bytes and the pattern length is 999 bytes. This causes the Go runtime to detect invalid slice bounds, resulting in a non-recoverable panic that terminates the process immediately.
Recommendations Update to version 0.73.1.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53432

Affected Products

Fzf