VulnSea

vgmstream vulnerabilities

CVEs whose affected-version data names the vgmstream package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-92881Medium· 4.3
4d ago

A security vulnerability has been detected in vgmstream

A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads to divide by zero. The attack can be …

SunlitEPSS 0.34%via NVD
CVE-2026-92880Medium· 6.3
4d ago

A weakness has been identified in vgmstream up to r2117

A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of…

SunlitEPSS 0.25%via NVD
CVE-2026-92879Medium· 4.3
4d ago

A security flaw has been discovered in vgmstream up to r2117

A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is i…

SunlitEPSS 0.43%via NVD
CVE-2026-86515Medium· 4.3PoC
1w ago

A security vulnerability has been detected in vgmstream up to r2117

A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource c…

TwilightEPSS 0.34%via NVD
CVE-2026-86514Medium· 6.3PoC
1w ago

A weakness has been identified in vgmstream up to r2117

A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be ca…

TwilightEPSS 0.27%via NVD
vgmstream vulnerabilities (CVEs) · VulnSea