CVE-2026-95509EPSS p21.8%

CVE-2026-95509CVE-2026-95509

Description

Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.

Scoring

EPSS0.31% probability of exploitation · percentile 21.8% · 2026-10-05T12:00:23Z
Last modified2026-09-30
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.