CVE-2020-1896
NixOS vulnerability analysis and mitigation

Overview

A stack overflow vulnerability was identified in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2. This vulnerability affects applications that use Hermes to execute untrusted JavaScript code (CVE Details).

Technical details

The vulnerability stems from a missing check for stack overflow in the Hermes JavaScript engine's builtin apply functionality. The issue was fixed by adding a stack overflow check in the hermesBuiltinApply function (Hermes Commit).

Impact

If exploited, this vulnerability could potentially allow attackers to execute arbitrary code via crafted JavaScript. However, this is only exploitable in cases where Hermes is used to execute untrusted JavaScript, meaning most React Native applications are not affected (CVE Details).

Mitigation and workarounds

The vulnerability was patched in commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2. Users should update to a version of Hermes that includes this fix. Additionally, applications should avoid executing untrusted JavaScript code when possible (Hermes Commit).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68981HIGH8.8
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-69153MEDIUM6.3
  • JavaScript logoJavaScript
  • pcs
NoYesAug 03, 2026
CVE-2026-68979MEDIUM5.9
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-68980LOW2.3
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-54522LOW2.1
  • Ruby logoRuby
  • ruby4.0-msgpack
NoYesJul 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management