Out-of-Bounds Read Vulnerability in Stb Library by Nothings
CVE-2026-79516

4MEDIUM

Key Information:

Vendor

Nothings

Vendor
CVE Published:
9 September 2026

What is CVE-2026-79516?

An out-of-bounds read vulnerability exists in the stbsp_vsnprintf function within the stb_sprintf.h file of the Stb library maintained by Nothings. This vulnerability allows attackers to send specially crafted inputs that can trigger a Denial of Service condition, potentially disrupting service availability. Users of affected versions are encouraged to evaluate their exposure to this risk and apply necessary mitigations as outlined in the issue tracker.

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.