Out-of-Bounds Read Vulnerability in Turso Database by Tursodatabase
CVE-2026-85698

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85698?

Turso through version 0.8.0-pre.8 is susceptible to an out-of-bounds read vulnerability that exploits a flaw within its table-leaf page reader. This vulnerability allows attackers to manipulate the cell-count field without adequate bounds validation. By crafting a malicious database file with a tampered cell count value, an attacker can trigger an index-out-of-bounds panic when the database is queried. This situation potentially results in Denial of Service for any application that processes untrusted database files, creating significant operational disruptions.

Affected Version(s)

turso 0 <= 0.8.0-pre.8

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.