drlibs drflac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac_readanddecodemetadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.
{
"cwe_ids": [
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32836.json",
"cna_assigner": "VulnCheck"
}{
"cpe": "cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.13.3"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-08-12T15:32:28Z"
[
{
"id": "CVE-2026-32836-433925cb",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 10723.0,
"function_hash": "263877883709673697127533507054059527641"
},
"source": "https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676",
"target": {
"function": "drflac__read_and_decode_metadata",
"file": "dr_flac.h"
}
},
{
"id": "CVE-2026-32836-75e6274e",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"239453336896498647652828486810239642674",
"46576341553487246220612096141880806594",
"316137208537675378201811604300593086587",
"256710093781893194579228782733319349911",
"326170709788470511574172942760317697619",
"277637927234007055121583992636272992437",
"170455584214542869459599082284592249221",
"297373028930806465255451570640489466189",
"166357148870445037158725702856976685784"
]
},
"source": "https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8",
"target": {
"file": "dr_flac.h"
}
},
{
"id": "CVE-2026-32836-b967df33",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"312098584394681776007184099119548608788",
"156795787947303449052969177408990759377",
"230589701935222855554839073967535236708",
"79555147284346167299777022351548481719",
"75352035980912294100526432300105411848",
"283318800769506464223620764598937038807",
"160366924805719731352282503008834715765",
"193551421593112871500734533425905952506",
"127393314191519298840106846926157382787",
"60984747867211332558045335830138746820",
"311472631558505686306470143602637292431",
"290877997238418456864023098957039727430",
"263529883509795293594817901859378992771",
"103137645577131216360093940240659123655"
]
},
"source": "https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676",
"target": {
"file": "dr_flac.h"
}
},
{
"id": "CVE-2026-32836-d4399a31",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 10769.0,
"function_hash": "242963734227876497380352942408454134200"
},
"source": "https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8",
"target": {
"function": "drflac__read_and_decode_metadata",
"file": "dr_flac.h"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32836.json"