CVE-2020-1896
NixOS vulnerability analysis and mitigation

Overview

A stack overflow vulnerability was identified in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2. This vulnerability affects applications that use Hermes to execute untrusted JavaScript code (CVE Details).

Technical details

The vulnerability stems from a missing check for stack overflow in the Hermes JavaScript engine's builtin apply functionality. The issue was fixed by adding a stack overflow check in the hermesBuiltinApply function (Hermes Commit).

Impact

If exploited, this vulnerability could potentially allow attackers to execute arbitrary code via crafted JavaScript. However, this is only exploitable in cases where Hermes is used to execute untrusted JavaScript, meaning most React Native applications are not affected (CVE Details).

Exploitability

The vulnerability requires the application using Hermes to permit evaluation of untrusted JavaScript code. The exploit can be triggered through specially crafted JavaScript that causes a stack overflow in the builtin apply function (Hermes Commit).

Mitigation and workarounds

The vulnerability was patched in commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2. Users should update to a version of Hermes that includes this fix. Additionally, applications should avoid executing untrusted JavaScript code when possible (Hermes Commit).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management