Junglewise Threat Intelligence

CVE-2026-90786: Dvidelabs flatcc reachable assertion in align_order_members

CVE-2026-90786 · Severity: medium · CVSS 5.3 · Published 2026-09-14

Technologies: Dvidelabs Flatcc. Vendors: Dvidelabs.

Executive brief

flatcc is a FlatBuffers compiler for C that translates schema files into C code. When a user accidentally declares the same table member twice in a schema file, the compiler crashes with an assertion error instead of reporting a proper syntax error. This denial-of-service vulnerability could disrupt development workflows and CI/CD pipelines that rely on flatcc for code generation.

Technical details

The vulnerability is a reachable assertion (CWE-617) in the align_order_members() function at src/compiler/semantics.c:1059. When a table member is declared twice, the duplicate entry's computed sort_key value collapses to 0, triggering the assertion `assert(k > 0)` and aborting the compiler with SIGABRT. The root cause is insufficient validation during semantic analysis; duplicate member names should be caught as redefinition errors before the ordering phase. The attack vector is attacker-controlled .fbs schema text, requiring no authentication or network access. A fix is available in commit 8b19ba4e992ebcad7f5970704d1afc5507fa5205.

Affected products

  • Dvidelabs flatcc up to 0.6.3

Timeline

  • 2026-09-14: disclosed
  • 2026-08-04: other: Bug report filed on GitHub issue #387
  • other: Patch available: commit 8b19ba4e992ebcad7f5970704d1afc5507fa5205

References

Related threats