CVE-2026-102805: Nothings Stb
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.
Affected products
- Nothings Stb: version 1.0 only; version 1.1 only; version 1.2 only; version 1.3 only; version 1.4 only; version 1.5 only; …
Published 2026-09-30. Last modified 2026-10-01.