Junglewise Threat Intelligence

CVE-2026-18852: Epsilla VectorDB filter parser unmatched parenthesis crash

CVE-2026-18852 · Severity: low · CVSS 3.3 · Published 2026-08-05

Executive brief

Epsilla VectorDB is a vector database engine used for similarity search and embedding storage. A vulnerability in its filter parsing component allows a local attacker to craft malformed filter expressions that cause the parser to crash, potentially leading to denial of service. The vendor has not responded to disclosure notifications.

Technical details

The vulnerability exists in the Filter Parser component of epsilla-cloud/vectordb, specifically in the SplitTokens/ShuntingYard functions within engine/query/expr/expr.cpp. The parser does not properly validate filter expressions and fails to detect unmatched closing parentheses. When a malformed expression like "2)e+" is parsed, the ShuntingYard algorithm unconditionally attempts to pop from an empty operator stack, causing undefined behavior, memory corruption, or application termination. The attack requires local access and can be triggered via crafted filter expressions. The vulnerability has been disclosed publicly with a proof-of-concept, and the vendor has not provided a fix.

Affected products

  • Epsilla VectorDB up to 0.3.18

Timeline

  • 2026-08-05: disclosed
  • other: Exploit PoC publicly available on GitHub fa1c4/security-advisories

References