CVE-2026-102805Medium· 6.5▾ SunlitA flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102804Medium· 6.5A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20
CVE-2026-7598High· 7.3A security vulnerability has been detected in libssh2 up to 1.11.1
CVE-2026-102621Low· 3.3A vulnerability was identified in Freedesktop Poppler up to 26.08.0
CVE-2026-102620Low· 3.3A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0
CVE-2026-101279Medium· 6.5A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2
CVE-2026-94030Low· 3.1A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c