7.1
CVE-2026-18497
- EPSS 0.12%
- Veröffentlicht 07.08.2026 14:19:42
- Zuletzt bearbeitet 08.09.2026 14:07:24
- Erkennungen
The nothings stb TrueType library contains a heap buffer overflow vulnerability
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed TTF (TrueType Font) files. The vulnerability resides in the glyph data parsing path. An attacker can craft a malformed TTF file with an inflated endPtsOfContours value and truncate the remaining glyph data. When an application utilizing stb_truetype.h (such as various game engines or graphics software) attempts to load, bake, or render this malformed font via stbtt_GetGlyphShape(), the parser will attempt to read past the end of the glyph data buffer, triggering the out-of-bounds read.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSean Barrett (nothings)
≫
Produkt
nothings stb
Version
1.26
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.026 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://cwe.mitre.org/data/definitions/122.html
https://github.com/nothings/stb
https://github.com/nothings/stb/issues/1905
https://kb.cert.org/vuls/id/987105
https://www.kb.cert.org/vuls/id/987105