CVE-2023-45661: Nothings Stb Image.h

High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.

stb_image is a single file MIT licensed library for processing images. A crafted image file may trigger out of bounds memcpy read in `stbi__gif_load_next`. This happens because two_back points to a memory address lower than the start of the buffer out. This issue may be used to leak internal memory allocation information.

Affected products

Published 2023-10-21. Last modified 2026-06-17.