CVE-2026-105248Medium· 6.3▾ SunlitA security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92880Medium· 6.3A weakness has been identified in vgmstream up to r2117
CVE-2026-86514Medium· 6.3A weakness has been identified in vgmstream up to r2117
CVE-2026-105251Medium· 6.3vgmstream VAG File psx_decoder.c ps_find_padding out-of-bounds
CVE-2026-105249Medium· 4.8A weakness has been identified in vgmstream up to r2117
CVE-2026-105250Medium· 4.3A security vulnerability has been detected in vgmstream up to r2117
CVE-2026-92881Medium· 4.3A security vulnerability has been detected in vgmstream