{"id":"CVE-2025-15536","aliases":["GHSA-5pr6-crvp-2j9f"],"url":"https://o3.security/vulnerability/CVE-2025-15536","summary":"BYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflow","details":"A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. Patch name: 345c9a50ab07018f1b4439776bad78a0d40778ec. To fix this issue, it is recommended to deploy a patch.","published":"2026-01-18T09:02:12.026Z","modified":"2026-08-12T15:13:20.132752Z","cvss":null,"epss":{"score":0.00256,"percentile":0.17474,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"opencc","fixedVersion":"1.2.0"}],"fix":{"url":"https://github.com/BYVoid/OpenCC/commit/345c9a50ab07018f1b4439776bad78a0d40778ec","label":"BYVoid/OpenCC@345c9a5"},"references":[{"type":"WEB","url":"https://github.com/BYVoid/OpenCC/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15536.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15536"},{"type":"ADVISORY","url":"https://vuldb.com/?id.341708"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.733347"},{"type":"REPORT","url":"https://github.com/BYVoid/OpenCC/issues/997"},{"type":"REPORT","url":"https://github.com/BYVoid/OpenCC/pull/1005"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.341708"},{"type":"FIX","url":"https://github.com/BYVoid/OpenCC/commit/345c9a50ab07018f1b4439776bad78a0d40778ec"},{"type":"EVIDENCE","url":"https://github.com/oneafter/1222/blob/main/repro"},{"type":"PACKAGE","url":"https://github.com/BYVoid/OpenCC"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:13:20.132752Z"}}