Out-of-Bounds Read Vulnerability in Stb Library by Nothings
CVE-2026-79516
4MEDIUM
What is CVE-2026-79516?
An out-of-bounds read vulnerability exists in the stbsp_vsnprintf function within the stb_sprintf.h file of the Stb library maintained by Nothings. This vulnerability allows attackers to send specially crafted inputs that can trigger a Denial of Service condition, potentially disrupting service availability. Users of affected versions are encouraged to evaluate their exposure to this risk and apply necessary mitigations as outlined in the issue tracker.
