CVE-2026-71261: Mackron Dr Libs
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk, a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to size_t before dividing by DRWAV_CUE_POINT_BYTES; on 32-bit builds this truncation causes the pre-allocated extra metadata capacity to be computed incorrectly.
Affected products
- Mackron Dr Libs: any version
Published 2026-08-05. Last modified 2026-08-26.