VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability
Imported from official source
Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. Description The nothings stb repository, versions 1.26 and earlier, contains a collection of single-file public domain and MIT-licensed libraries for C/C++ projects. CVE-2026-18497 A heap buffer overflow vulnerability exists in the stbtt_GetGlyphShape() function within the stb_truetype.h library when handling malformed TrueType Font (TTF) da...
This version
- Version
- 1 of 1
- Recorded
- September 15, 2026 20:57
- Change
- Initial
- Content hash
7e50482caafcd420c2adf89731a528b5- All versions
- Revision history