A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 30 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.
Title Nothings stb Image Encoding stb_image_write.h stbi_write_tga_core integer overflow
First Time appeared Nothings
Nothings stb
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:nothings:stb:*:*:*:*:*:*:*:*
Vendors & Products Nothings
Nothings stb
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T00:15:17.198Z

Reserved: 2026-09-29T17:08:48.761Z

Link: CVE-2026-102805

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T01:16:36.187

Modified: 2026-09-30T01:16:36.187

Link: CVE-2026-102805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses