CVE-2026-102804Medium· 6.5▾ SunlitA vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample resul…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102805Medium· 6.5A flaw has been found in Nothings stb up to 1.16
CVE-2026-7598High· 7.3A security vulnerability has been detected in libssh2 up to 1.11.1
CVE-2026-102621Low· 3.3A vulnerability was identified in Freedesktop Poppler up to 26.08.0
CVE-2026-102620Low· 3.3A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0
CVE-2026-101279Medium· 6.5A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2
CVE-2026-94030Low· 3.1A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c