Missing Release of Memory after Effective Lifetime Affecting openwrt package, versions [,24.10.6)[25.12.0-rc1,25.12.1)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.52% (40th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Release of Memory after Effective Lifetime vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-OPENWRT-15809132
  • published29 Mar 2026
  • disclosed20 Mar 2026
  • creditaxelm-tob

Introduced: 20 Mar 2026

CVE-2026-30873  (opens in a new tab)
CWE-401  (opens in a new tab)

How to fix?

Upgrade openwrt to version 24.10.6, 25.12.1 or higher.

Overview

Affected versions of this package are vulnerable to Missing Release of Memory after Effective Lifetime in the jp_get_token function. An attacker can cause increased memory consumption by submitting specially crafted input expressions that trigger repeated extraction of string literals, field labels, or regular expressions, leading to memory not being freed properly.

CVSS Base Scores

version 4.0
version 3.1