Heap Buffer Overflow Vulnerability in nothings stb TrueType Library
CVE-2026-18497

Currently unrated

Key Information:

Vendor
CVE Published:
7 August 2026

What is CVE-2026-18497?

A vulnerability exists in the nothings stb TrueType library, particularly in version 1.26 and earlier, which pertains to the parsing of malformed TrueType Font (TTF) files. The flaw is centered around the stbtt__GetGlyphShapeTT() function, where improper handling of glyph data can lead to an out-of-bounds read. Attackers may exploit this by crafting a specially designed TTF file that contains an exaggerated endPtsOfContours value while truncating the corresponding glyph data. When applications utilizing the stb_truetype.h library attempt to load or render these malformed files, it can trigger the vulnerability, potentially compromising system security within graphics software or game engines that incorporate this library.

Affected Version(s)

nothings stb 1.26

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.