5

CVE-2026-5313

Nothings stb GIF Decoder stb_image.h stbi__gif_load_next denial of service

A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNothings
Produkt stb
Version 2.0
Status affected
Version 2.1
Status affected
Version 2.2
Status affected
Version 2.3
Status affected
Version 2.4
Status affected
Version 2.5
Status affected
Version 2.6
Status affected
Version 2.7
Status affected
Version 2.8
Status affected
Version 2.9
Status affected
Version 2.10
Status affected
Version 2.11
Status affected
Version 2.12
Status affected
Version 2.13
Status affected
Version 2.14
Status affected
Version 2.15
Status affected
Version 2.16
Status affected
Version 2.17
Status affected
Version 2.18
Status affected
Version 2.19
Status affected
Version 2.20
Status affected
Version 2.21
Status affected
Version 2.22
Status affected
Version 2.23
Status affected
Version 2.24
Status affected
Version 2.25
Status affected
Version 2.26
Status affected
Version 2.27
Status affected
Version 2.28
Status affected
Version 2.29
Status affected
Version 2.30
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.152
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@vuldb.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
cna@vuldb.com 2.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-404 Improper Resource Shutdown or Release

The product does not release or incorrectly releases a resource before it is made available for re-use.