CVE-2026-47271: Getenv Modification Mutator

The pointer returned by `getenv()` refers directly to the process environment block. Modifying this memory invokes undefined behavior and can corrupt the environment or crash the program. Functions like `strtok`, `strtok_r`, and `strsep` modify the string in-place by inserting null terminators. Always copy the string (e.g., using `strdup()`) before parsing o

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-47271-getenv-modification-mutator --engine opengrep

Description

The pointer returned by `getenv()` refers directly to the process environment block. Modifying this memory invokes undefined behavior and can corrupt the environment or crash the program. Functions like `strtok`, `strtok_r`, and `strsep` modify the string in-place by inserting null terminators. Always copy the string (e.g., using `strdup()`) before parsing o