CVE-2026-33491Disclosure(zenc-lang / zen_c)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch zenc-lang zen_c systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based buffer overflow vulnerability in the Zen C compiler allows attackers to cause a compiler crash or potentially execute arbitrary code by providing a specially crafted Zen C source file (`.zc`) with excessively long struct, function, or trait identifiers. Users are advised to update to Zen C version v0.4.4 or later to receive a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zen_c

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-26)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
zen_c

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 1Mentions · 2026-03-26: 2Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-26: 203-2003-26
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-201
Patch1
2026-03-262
Disclosure2
Full discourse3 posts
  • Zuhaitz@zuhaitz_dev
    Patch

    New security advisory published for Zen C, this time it was about a stack-based buffer overflow in identifier mangling. CVE for it is CVE-2026-33491. As always, move to the latest version, in this case v0.4.4. Here's the link for it: https://github.com/zenc-lang/zenc/security/advisories/GHSA-rv74-w6q7-h8xr

    Post summary

    The advisory discloses a stack‑based buffer overflow (CVE‑2026‑33491) in Zen C and recommends upgrading to version v0.4.4 to mitigate the vulnerability.

    100112366
    6.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33491 Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based buffer overflow vulnerability in the Zen C co… https://www.cve.org/CVERecord?id=CVE-2026-33491

    Post summary

    The post announces CVE‑2026‑33491, a stack‑based buffer overflow in Zen C affecting versions before 0.4.4, with no PoC, exploitation evidence, or patch details provided.

    00000186
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33491 - Zen-C has Stack-Based Buffer Overflow in Identifier Mangling Intel Report: https://ift.tt/gtQZpM2

    Post summary

    The alert announces a stack‑based buffer overflow in Zen‑C (CVE‑2026‑33491) with no PoC, exploit, or mitigation details shared.

    0000027
    285 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzenc-langzen_c---

Explore more