CVE-2026-82605

Summary

A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.

Affected Software

VendorProductVersion RangeStatus
BareBonesBBEdit15.5.0affected
BareBonesBBEdit15.5.1affected
BareBonesBBEdit15.5.2affected
BareBonesBBEdit15.5.3affected
BareBonesBBEdit15.5.4affected
BareBonesBBEdit15.5.5affected
BareBonesBBEdit16.0unaffected

Weaknesses

  • CWE-835: Infinite Loop
  • CWE-404: Denial of Service

References