CVE-2025-11015: Ogrecave Ogre

Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp. This manipulation causes mismatched memory management routines. The attack is restricted to local execution. The exploit has been made available to the public and could be exploited.

Affected products

  • Ogrecave Ogre: version 14.4.0 only; version 14.4.1 only

Published 2025-09-26. Last modified 2026-10-09.