A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6 (2025-12-11), in file gc_decref_child in quickjs.c, when executed with the qjs interpreter using the -m option. This leads to an abort (SIGABRT) during garbage collection and causes a denial-of-service.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/bellard/quickjs/issues/467 |
|
History
Fri, 06 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6 (2025-12-11), in file gc_decref_child in quickjs.c, when executed with the qjs interpreter using the -m option. This leads to an abort (SIGABRT) during garbage collection and causes a denial-of-service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-06T18:38:40.772Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69653
No data.
Status : Received
Published: 2026-03-06T19:16:11.040
Modified: 2026-03-06T19:16:11.040
Link: CVE-2025-69653
No data.
OpenCVE Enrichment
No data.