CVE-2020-26682: Libass Project Libass
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
In libass 0.14.0, the `ass_outline_construct`'s call to `outline_stroke` causes a signed integer overflow.
Affected products
- Libass Project Libass: version 0.14.0 only
Published 2020-10-16. Last modified 2026-06-17.