PatchSiren

trabucayre CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH trabucayre CVE published 2026-04-06

CVE-2026-35170

A heap-buffer-overflow read vulnerability exists in openFPGALoader 1.1.1 and earlier in BitParser::parseHeader(). This allows out-of-bounds heap memory access when parsing a crafted .bit file, without requiring FPGA hardware. The vulnerability has a high CVSS score of 7.1, indicating high severity. Users of openFPGALoader 1.1.1 and earlier should apply patches or mitigations to prevent potential out-of-bo [truncated]