Description
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Integer overflow in stb image encoding functions leading to possible remote exploitation
Action: Patch
AI Analysis

Impact

A flaw in Nothings' stb image library up to version 1.16 can cause an integer overflow when encoding PNG, JPG, or TGA images. The overflow occurs in the stbi_write_* core functions of stb_image_write.h and can corrupt memory or overwrite critical data. This vulnerability can be triggered remotely by providing a crafted image, and published exploits may already be available, potentially allowing arbitrary code execution or denial of service.

Affected Systems

Nothings’ stb image library, all releases up to and including version 1.16. No specific sub‑versions are enumerated, so any build of stb prior to the next released version is considered vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, but the lack of an EPSS score means the probability of exploitation is currently uncertain. The vulnerability is remotely exploitable without authentication and is not listed in the CISA KEV catalog. Since published exploits exist, this risk is compounded, and attackers can potentially abuse the integer overflow to achieve arbitrary memory writes or code execution with suitable crafted inputs.

Generated by OpenCVE AI on September 30, 2026 at 07:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the newest stb release (1.17 or later) which contains the fix for the integer overflow in the image encoding functions.
  • If an immediate upgrade is not possible, patch the stb source to add bounds checks that prevent width·height or other dimension calculations from overflowing before they are used in memory allocation.
  • Validate or sanitize all image dimensions and data before passing them to stb_image_write functions, rejecting images that would cause large or negative allocation sizes to mitigate exploitation risk.

Generated by OpenCVE AI on September 30, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.
Title Nothings stb Image Encoding stb_image_write.h stbi_write_tga_core integer overflow
First Time appeared Nothings
Nothings stb
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:nothings:stb:*:*:*:*:*:*:*:*
Vendors & Products Nothings
Nothings stb
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T00:15:17.198Z

Reserved: 2026-09-29T17:08:48.761Z

Link: CVE-2026-102805

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T01:16:36.187

Modified: 2026-09-30T14:04:38.183

Link: CVE-2026-102805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses