Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85698— Turso through 0.8.0-pre.8 Out-of-Bounds Read Denial of Service

Quick assessment

Affected
tursodatabase turso
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Turso 在 0.8.0-pre.8 之前的版本中,其表叶页面读取器存在一个越界读取漏洞。该漏洞源于读取器使用攻击者可控的单元格计数(cell-count)字段,但未进行边界校验。攻击者可以通过构造一个恶意数据库文件,修改其中的单元格计数值,从而在查询时触发索引越界引发的 panic(程序崩溃)。任何打开不受信任数据库文件的应用程序都可能因此遭受服务拒绝(DoS)攻击。

CVSS 5.5 · Medium

Possible ATT&CK Techniques 1 AI

T1059.003 · Windows Command Shell

Affected Version Matrix 1

VendorProduct Version RangeStatus
tursodatabase turso ≤ 0.8.0-pre.8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85698

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Turso through 0.8.0-pre.8 Out-of-Bounds Read Denial of Service
Source: CVE Program / CVE List V5
Vulnerability Description
Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modified cell count value to trigger an index-out-of-bounds panic when querying, causing denial of service in any application that opens untrusted database files.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
tursodatabase turso 0 ~ 0.8.0-pre.8 -

II. Public POCs for CVE-2026-85698

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85698

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85698 (1)

Proof of Concept for CVE-2026-85698 (1)

Other References for CVE-2026-85698 (1)

Other References for CVE-2026-85698 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85698

No comments yet


Leave a comment