Heap Out-of-Bounds Read Vulnerability in miniaudio by Mackron
CVE-2026-32837
5.1MEDIUM
What is CVE-2026-32837?
The miniaudio library, particularly versions 0.11.25 and earlier, is susceptible to a heap out-of-bounds read due to an issue in the WAV BEXT metadata parser. Attackers can exploit this vulnerability by crafting malicious WAV files that improperly handle null-termination in the coding history field. This can lead to memory access violations, causing application crashes or a denial of service. Developers using miniaudio should upgrade to address this issue.
Affected Version(s)
miniaudio 0 <= 0.11.25
miniaudio 1df46ae9a0eed5aa9f58b179d2cc4af5d23f8bde
