CVE-2026-95125

EPSS: 0.2% chance of exploitation in the next 30 days.

libming through 0.4.8 contains a heap buffer overflow in r_readc() in src/blocks/fromswf.c. A crafted SWF file with a malformed or truncated RECT header can cause a denial of service.

Published 2026-10-08. Last modified 2026-10-08.