Nothings has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.5 (medium). Most affected products: stb (2), stb_vorbis (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-89266High· 8.2stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int57CVE-2026-102805Medium· 6.5A flaw has been found in Nothings stb up to 1.1636CVE-2026-102804Medium· 6.5A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd2036
Nothings vulnerabilities
CVEs affecting Nothings, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-102804Medium· 6.5A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20
A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample resul…
CVE-2026-102805Medium· 6.5A flaw has been found in Nothings stb up to 1.16
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead…
CVE-2026-89266High· 8.2PoCstb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int
stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimension…