Out-of-Bounds Read Vulnerability in berry-lang Berry Software
CVE-2026-3285
Key Information:
- Vendor
Berry-lang
- Status
- Vendor
- CVE Published:
- 27 February 2026
Badges
What is CVE-2026-3285?
A vulnerability exists in the berry-lang Berry software prior to version 1.1.0, specifically in the scan_string function located in src/be_lexer.c. This flaw allows for out-of-bounds reads, which can potentially lead to exposure of sensitive data. The vulnerability requires local access to exploit, making it essential for users to secure their environments. A fix has been made available, noted in commit 7149c59a39ba44feca261b12f06089f265fec176, and it is strongly advised to apply this patch to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
berry 1.0
berry 1.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
