CVE-2026-102804: Nothings stb stb_hexwave.h hexwave_init integer overflow
A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwaveinit in the library stbhexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What deployments are exposed to this issue?
Deployments using Nothings stb versions up to commit 2c980bb59875b0d32144a71867fbdebb2f77cd20 are affected when they use the stb_hexwave.h library and call hexwave_init with attacker-influenced width or oversample values.
Does exploitation require authentication or user interaction?
No. The supplied severity vector indicates network attack access, low attack complexity, no privileges, and no user interaction.
How can I determine whether my application is affected?
Identify the stb revision included or vendored by the application, then check whether it is at or before commit 2c980bb59875b0d32144a71867fbdebb2f77cd20. Also review uses of stb_hexwave.h and hexwave_init to determine whether untrusted input can control the width or oversample arguments.
What is the risk if an exploit succeeds?
The provided assessment assigns low integrity and availability impact, with no confidentiality impact. Public exploit code is reported to be available.