Junglewise Threat Intelligence

theopolis uefi-firmware-parser stack out-of-bounds write in MakeTable

Severity: critical · CVSS 9.8 · Published 2026-04-16

Technologies: Theopolis Uefi-Firmware-Parser, uefi-firmware (PyPI). Vendors: Theopolis, PyPI.

Executive brief

The uefi-firmware-parser library contains a stack-based out-of-bounds write vulnerability in its Tiano/EFI decompression engine. A crafted firmware blob can trigger memory corruption, leading to a crash or potential remote code execution.

Affected products

  • theopolis uefi-firmware-parser
  • PyPI uefi-firmware

Related threats