CVE-2019-20056: Nothings Stb Image.h

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.

Affected products

Published 2019-12-29. Last modified 2026-06-17.