VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability

CERT Coordination Center Version 1 original current

Imported from official source

Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. Description The nothings stb repository, versions 1.26 and earlier, contains a collection of single-file public domain and MIT-licensed libraries for C/C++ projects. CVE-2026-18497 A heap buffer overflow vulnerability exists in the stbtt_GetGlyphShape() function within the stb_truetype.h library when handling malformed TrueType Font (TTF) da...

This version

Version
1 of 1
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
7e50482caafcd420c2adf89731a528b5
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.