CVE-2026-86514Medium· 6.3▾ TwilightPoC availableA weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be ca…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 34.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Exploit / PoC code exists
0.3% → 0.5%
A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 4669d37a6af94866f6f0628678f9f90d46954e8b. To fix this issue, it is recommended to deploy a patch.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92880Medium· 6.3A weakness has been identified in vgmstream up to r2117
CVE-2026-86515Medium· 4.3A security vulnerability has been detected in vgmstream up to r2117
CVE-2026-92881Medium· 4.3A security vulnerability has been detected in vgmstream
CVE-2026-92879Medium· 4.3A security flaw has been discovered in vgmstream up to r2117
CVE-2026-86509Critical· 9.6A flaw has been found in D-Link DIR-895L A1_102b07
CVE-2026-86318Medium· 5.3A flaw has been found in java-json-tools json-patch up to 1.13