
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40447 is an integer overflow or wraparound vulnerability (CWE-190) in Samsung Open Source Escargot, a lightweight JavaScript engine. The vulnerability allows undefined behavior and can be exploited to cause a denial of service condition. It affects Escargot at commit 97e8115ab1110bc502b4b5e4a0c689a71520d335 (dated 2026-03-28). Disclosed on April 13, 2026, it carries a CVSS v3.1 base score of 7.5 (High) per NVD, though the GitHub Advisory Database and ENISA EUVD rate it at 5.1 (Moderate) using a local attack vector (GitHub Advisory, Red Hat Bugzilla).
The root cause is an integer overflow or wraparound (CWE-190) within the Escargot JavaScript engine, where arithmetic operations on integer values can exceed the representable range, causing the value to wrap around to an unexpected small or negative number, leading to undefined behavior. The fix, merged via pull request #1554 on April 8, 2026, addressed multiple minor issues including buffer size validation in CodeCacheReader and input validation in Serializer::deserializeFrom, suggesting the overflow may be related to deserialization or code cache processing logic (GitHub PR #1554). The NVD CVSS vector indicates a network-based attack with no privileges or user interaction required, while the GitHub Advisory scores it as a local, high-complexity attack — indicating some ambiguity in the precise attack surface (GitHub Advisory).
The primary impact of this vulnerability is on availability: a successful exploit can crash applications or services that embed the Escargot JavaScript engine, resulting in a denial of service condition through integer wraparound. There is no impact on confidentiality or integrity based on the CVSS scoring. The scope is limited to the affected component, with no evidence of lateral movement potential or data exposure risk (GitHub Advisory, Red Hat Bugzilla).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.013% (0.000130), placing it in a very low probability tier for near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).
A patch is available via Samsung Escargot pull request #1554, merged on April 8, 2026, which addresses the integer overflow along with related input validation and buffer size checking issues. Organizations should update their Escargot dependency to a commit after f25f05f (post-PR #1554 merge into the master branch). Until patching is complete, restricting local access to systems running the vulnerable version is advised as a temporary measure (GitHub PR #1554, GitHub Advisory).
Red Hat's Product Security team tracked this vulnerability via Bugzilla (Bug 2457772) with medium priority and severity, indicating awareness within the Linux ecosystem where Escargot may be packaged. No significant public researcher commentary or media coverage has been identified beyond standard vulnerability database entries (Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."