Junglewise Threat Intelligence

CVE-2026-53432: junegunn fzf integer overflow in FuzzyMatchV2

CVE-2026-53432 · Severity: info · CVSS 5.6 · Published 2026-06-30

Executive brief

fzf is a popular command-line tool used for quickly searching and filtering lists of files or data. A vulnerability in its matching engine can cause the tool to crash when processing extremely long lines of text combined with specific search patterns. This results in a denial-of-service where the tool becomes unusable for certain datasets, though it does not directly expose sensitive information.

Technical details

An integer overflow exists in the `FuzzyMatchV2` function within `src/algo/algo.go`, specifically affecting 32-bit architectures (e.g., ARM, x86). When the product of the input line length (N) and the pattern length (M) exceeds the capacity of a 32-bit signed integer, the value wraps to a negative number. This bypasses existing safety checks intended to trigger a fallback to the V1 algorithm. Consequently, the Go runtime attempts to allocate a slice with a negative bound, resulting in a non-recoverable panic and process termination. The issue is triggered when input lines are approximately 2.2 million bytes and the search pattern is near 1,000 bytes. This was fixed in version 0.73.1 by casting operands to 64-bit integers before multiplication.

Affected products

  • junegunn fzf All versions before 0.73.1

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory
  • 2026-06-30: patched: Fixed in version 0.73.1

References