CVE-2026-102805

Summary

A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.

Affected Software

VendorProductVersion RangeStatus
Nothingsstb1.0affected
Nothingsstb1.1affected
Nothingsstb1.2affected
Nothingsstb1.3affected
Nothingsstb1.4affected
Nothingsstb1.5affected
Nothingsstb1.6affected
Nothingsstb1.7affected
Nothingsstb1.8affected
Nothingsstb1.9affected
Nothingsstb1.10affected
Nothingsstb1.11affected
Nothingsstb1.12affected
Nothingsstb1.13affected
Nothingsstb1.14affected
Nothingsstb1.15affected
Nothingsstb1.16affected

Weaknesses

  • CWE-190: Integer Overflow
  • CWE-189: Numeric Error

References