#antlr
🚨 EUVD-2026-86477
📊 8.7/10
🏢 Gerrit

📝 Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 thro...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86477

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 2:01 AM
And similarly, writing a grammar to use with ANTLR or Megaparsec or Tree-sitter or whatever is always going to be faster than "Claude, write me a parser for a language with the following spec...". But a world is being created where no one thinks to consider that.
September 6, 2026 at 3:45 PM
A dating app for deer called Antlr
August 28, 2026 at 7:14 AM
Muy de nicho esto:

youtu.be/5O2DqKtMltU?...
Evanesce (Remastered 2025)
YouTube video by ANTLR - Topic
youtu.be
July 15, 2026 at 6:51 PM
코드를 거의 보지 않고 만든 70배 빠른 SQL 파서

PostHog는 ANTLR 기반 C++ SQL 파서를 여러 Claude Code 세션으로 재작성해 16K줄의 Rust 파서 와 5K줄의 도구, 수천 줄의 테스트를 만들었으며 노트북 기준 약 70배의 속도 향상을 얻음 새 구현은 예측형 재귀 하강 파서 와 Pratt 표현식 코어를 중심으로, 필요한 곳...
코드를 거의 보지 않고 만든 70배 빠른 SQL 파서
PostHog는 ANTLR 기반 C++ SQL 파서를 여러 Claude Code 세션으로 재작성해 16K줄의 Rust 파서 와 5K줄의 도구, 수천 줄의 테스트를 만들었으며 노트북 기준 약 70배의 속도 향상을 얻음 새 구현은 예측형 재귀 하강 파서 와 Pratt 표현식 코어를 중심으로, 필요한 곳...
news.hada.io
July 15, 2026 at 3:00 AM
CVE-2026-13500 - Code Injection in ANTLR4 up to 4.13.2. CVSS 7.3. Remote exploit public, vendor unresponsive. Mitigate immediately. #CVE #infosec #ANTLR

https://www.valtersit.com/cve/CVE-2026-13500/
June 29, 2026 at 5:05 PM
CVE-2026-13500 - antlr ANTLR4 Grammar Action Block OutputFile.java code injection
CVE ID : CVE-2026-13500

Published : June 28, 2026, 2:15 p.m. | 3 hours, 30 minutes ago

Description : A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown func...
CVE-2026-13500 - antlr ANTLR4 Grammar Action Block OutputFile.java code injection
A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The exploit has been made available to the public …
cvefeed.io
June 28, 2026 at 6:16 PM
CVE-2026-13502 - antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou
CVE ID : CVE-2026-13502

Published : June 28, 2026, 2:45 p.m. | 3 hours ago

Description : A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ...
CVE-2026-13502 - antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou
A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This manipulation causes time-of-check time-of-use. The attack is restricted to local execution. A high degree of complexity is needed for the attack. It is indicated …
cvefeed.io
June 28, 2026 at 6:11 PM
CVE-2026-13501 - antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
CVE ID : CVE-2026-13501

Published : June 28, 2026, 2:30 p.m. | 3 hours, 15 minutes ago

Description : A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vul...
CVE-2026-13501 - antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The manipulation leads to command injection. The attack can only be performed from a local environment. The exploit has been disclosed publicly …
cvefeed.io
June 28, 2026 at 6:06 PM
CVE-2026-13503 - antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
CVE ID : CVE-2026-13503

Published : June 28, 2026, 3:15 p.m. | 2 hours, 30 minutes ago

Description : A vulnerability was detected in antlr ANTLR4 up to 4.13....
CVE-2026-13503 - antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The manipulation results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. …
cvefeed.io
June 28, 2026 at 6:01 PM
🚨 EUVD-2026-40001
📊 6.9/10
🏢 antlr

📝 A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/par...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40001

#cybersecurity #infosec #cve #euvd
June 28, 2026 at 5:00 PM
antlr ANTLR4 4.13.2以前に、OutputFile.javaの特定関数にコード注入の脆弱性があります。リモートから攻撃可能で、攻撃コードは公開されています。
CVE-2026-13500 CVSS 7.3 | HIGH
NVD - CVE-2026-13500
nvd.nist.gov
June 28, 2026 at 4:06 PM
🚨 EUVD-2026-39998
📊 6.9/10
🏢 antlr

📝 A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39998

#cybersecurity #infosec #cve #euvd
June 28, 2026 at 4:00 PM
🚨 EUVD-2026-39999
📊 4.8/10
🏢 antlr

📝 A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/an...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39999

#cybersecurity #infosec #cve #euvd
June 28, 2026 at 4:00 PM
🚨 EUVD-2026-40000
📊 2.0/10
🏢 antlr

📝 A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40000

#cybersecurity #infosec #cve #euvd
June 28, 2026 at 4:00 PM
PostHog successfully replaced its ANTLR-based SQL parser with a hand-rolled Rust version developed using Claude Code. By combining property-based testing with autonomous AI coding loops, the new parser achieves a 70x speedup while maintaining full accuracy.
I rewrote PostHog's SQL parser, 70x faster, while barely looking at the code (107)
After the success of using agents to improve query performance through autoresearch , I wanted to try something more ambitious. I rewrote PostHog's…
news.ycombinator.com
June 25, 2026 at 1:17 AM
Making progress with APEXlang support. The ANTLR4-based grammar can now parse the dbLinter APEX app without errors. Next step: more tests and integration into dbLinter’s language server.
June 21, 2026 at 3:12 PM
Oh no, i found ANTLR. And somewhere Bison was mentioned.

Is it time to start drinking?
May 30, 2026 at 2:56 PM
Explore ANTLR’s full trend breakdown on GitRanks using the link below. What factors might be driving this simultaneous drop in code size and contributor count? #github

https://gitranks.com/language/ANTLR/global/1?t=wGmJR5K5
May 24, 2026 at 10:40 AM
ANTLR’s codebase shrank from 287M to 276M bytes this month, and active contributors dipped from 2.5k to 2.2k. Both size and community metrics registered a pullback in the latest period. #ANTLR #github
May 24, 2026 at 10:30 AM
Lime is a new parser generator similar to Yacc, Bison, ANTLR, etc. save one thing... it's fast and has the ability to merge grammars at runtime. See the calculator example with + and - but then ^ for exponent, then ^ again for bitwise or. That can't work, right? codeberg.org/gregburd/lim...
Could run git maintenance run --schedule=weekly # END GIT MAINTENANCE SCHEDULE # The following will.
Empty message, when no <pathspec> is used. This format just.
codeberg.org
May 16, 2026 at 5:48 PM
I'm not sure it would be less work. The ANTLR syntax already exists, this is just making it nice to use.
May 8, 2026 at 2:55 PM
Well, custom lexing predicates are kind of unavoidable in ANTLR with context sensitive languages. If you're looking for someone to maintain a grammar, i am here, and i am ready xD
May 8, 2026 at 1:10 PM
Nice new project! :)

By the way, I think the lexer/parser part of the Kotlin compiler was separated some time ago. Keeping an ANTLR up-to-date is quite some work, and the Kotlin grammar has some quirks that are currently solved by custom code.
May 8, 2026 at 10:59 AM