CVE-2020-23914
Homebrew vulnerability analysis and mitigation

Overview

A NULL pointer dereference vulnerability was discovered in cpp-peglib through version 0.1.12 (CVE-2020-23914). The vulnerability exists in the peg::AstOptimizer::optimize() function located in peglib.h. This issue was reported in August 2020 and allows attackers to cause a Denial of Service condition (NVD, CVE).

Technical details

The vulnerability is caused by a NULL pointer dereference in the peg::AstOptimizer::optimize() function within peglib.h. The issue was discovered through testing with AddressSanitizer, which revealed a segmentation fault when accessing an invalid memory address. The CVSS v3.1 Base Score is 5.5 (Medium) with a vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (NVD).

Impact

When exploited, this vulnerability allows an attacker to cause a Denial of Service (DoS) condition in applications using the affected cpp-peglib library. The impact is limited to availability, with no direct effects on confidentiality or integrity of the system (NVD).

Exploitability

The vulnerability was demonstrated using a proof-of-concept test case that triggers a segmentation fault in the optimize() function. The issue can be reproduced using the peglint tool with specific command line arguments, as documented in the original bug report (GitHub Issue).

Mitigation and workarounds

A fix for this vulnerability was implemented in commit 0061f393de54cf0326621c079dc2988336d1ebb3. Users should upgrade to a version of cpp-peglib that includes this fix. The patch involves additional validation checks in the parser generator to prevent the NULL pointer dereference condition (GitHub Patch).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73939HIGH8.6
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73937HIGH8.2
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73938HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73936HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73935HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management