[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-53670":6},{"stargazers_count":4,"fetched_at":5},7,"2026-09-02T23:44:56.672Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":28,"aliases":29,"duplicate_of":9,"upstream":30,"downstream":31,"duplicates":32,"related":33,"reserved_at":9,"published_at":34,"modified_at":35,"state":36,"summary":37,"references_raw":44,"kevs":60,"epss":9,"epss_history":61,"metrics":62,"affected":69},"CVE-2026-53670","PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently skips offset-variable updates when the destination register carries a non-singleton typeset (two or more simultaneously possible pointer types). Subsequent bounds checks use the stale offset and accept out-of-bounds memory accesses, so a crafted BPF program passes verification even though it would corrupt memory at runtime. This issue has been patched in version 0.2.4.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-682","Incorrect Calculation","The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.","weakness","Draft","Pillar","High",[20,24],{"id":21,"name":22,"techniques":23},"CAPEC-128","Integer Attacks",[],{"id":25,"name":26,"techniques":27},"CAPEC-129","Pointer Manipulation",[],[],[],[],[],[],[],"2026-09-02T17:54:43.900Z","2026-09-02T18:08:29.456Z","Received",{"cisa_kev":38,"cisa_ransomware":38,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":39,"severity_score":40,"severity_version":41,"severity_source":42,"severity_vector":43,"severity_status":36},false,"critical",9.3,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",[45,51,56],{"url":46,"sources":47,"tags":49},"https://github.com/vbpf/prevail/security/advisories/GHSA-2qc8-qh94-66rc",[42,48],"nvd",[50],"X Refsource CONFIRM",{"url":52,"sources":53,"tags":54},"https://github.com/vbpf/prevail/commit/2b209bc4e3d612ff9aca87125e67c0ff84477e61",[42,48],[55],"X Refsource MISC",{"url":57,"sources":58,"tags":59},"https://github.com/vbpf/prevail/releases/tag/v0.2.4",[42,48],[55],[],[],[63,66],{"source":42,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":64},{"baseScore":40,"baseSeverity":65,"vectorString":43,"impactScore":9,"exploitabilityScore":9},"CRITICAL",{"source":48,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":67},{"baseScore":40,"baseSeverity":65,"vectorString":68,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[70],{"ecosystem":9,"name":71,"vendor":72,"product":71,"cpe_part":73,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":74},"prevail","vbpf","a",[75],{"version":76,"is_range":77,"range_type":42,"version_start":9,"version_start_type":9,"version_end":78,"version_end_type":79,"fixed_in":9},"\u003C 0.2.4",true,"0.2.4","excluding"]