CVE-2026-102805: Nothings stb Image Encoding stb_image_write.h stbi_write_tga_core integer overflow
Published Sep 30, 2026
·Updated
A flaw has been found in Nothings stb up to 1.16. This affects the function stbiwritepngtomem/stbiwritejpgcore/stbiwritetgacore in the library stbimagewrite.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
1 affected component
Nothings stb<=1.16
Event History
Sep 30, 2026
CVE Published
via MITRE·12:15 AM
Data Sourced
via MITRE·12:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which code paths should be prioritized for review?
Prioritize applications that use stb_image_write.h and invoke stbi_write_png_to_mem, stbi_write_jpg_core, or stbi_write_tga_core. The affected Nothings stb versions are up to 1.16.
2
Does an attacker need credentials or user interaction to exploit this issue?
No. The CVSS vector indicates network attack access with no privileges required and no user interaction required.
3
Is public exploit code available?
Yes. The exploit has been published, and the exploit maturity is rated as proof-of-concept.