vgmstream vulnerabilities
CVEs whose affected-version data names the vgmstream package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-92881Medium· 4.3A security vulnerability has been detected in vgmstream
A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads to divide by zero. The attack can be …
CVE-2026-92880Medium· 6.3A weakness has been identified in vgmstream up to r2117
A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of…
CVE-2026-92879Medium· 4.3A security flaw has been discovered in vgmstream up to r2117
A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is i…
CVE-2026-86515Medium· 4.3PoCA security vulnerability has been detected in vgmstream up to r2117
A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource c…
CVE-2026-86514Medium· 6.3PoCA weakness has been identified in vgmstream up to r2117
A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be ca…