Out-of-Bounds Read Vulnerability in stbtt_GetGlyphShape of nothings stb
CVE-2026-79515
4.3MEDIUM
What is CVE-2026-79515?
An out-of-bounds read vulnerability exists in the stbtt_GetGlyphShape component of nothings stb, which can be exploited by attackers to induce a Denial of Service (DoS) condition. By sending specially crafted TrueType Font (TTF) files, attackers can trigger this vulnerability, potentially leading to application crashes or other unintended behavior.
