CVE-2026-102804

Source
https://cve.org/CVERecord?id=CVE-2026-102804
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102804.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102804
Downstream
Published
2026-09-30T00:00:17Z
Modified
2026-10-08T02:49:13Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Nothings stb stb_hexwave.h hexwave_init integer overflow
Details

A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-189",
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102804.json"
}
References

Affected packages

Git / github.com/nothings/stb

Affected ranges

Type
GIT
Repo
https://github.com/nothings/stb
Events

Affected versions

Other
2c980bb59875b0d32144a71867fbdebb2f77cd20

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102804.json"