CVE-2026-5186: Nothings stb Multi-frame GIF File stb_image.h stbi__load_gif_main double free
A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbiloadgifmain of the file stbimage.h of the component Multi-frame GIF File Handler. This manipulation causes double free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5186?
CVE-2026-5186 has a medium severity rating due to the potential for exploitation leading to a double free vulnerability.
How do I fix CVE-2026-5186?
To fix CVE-2026-5186, you should upgrade Nothings stb to version 2.31 or later where the vulnerability has been addressed.
What software is affected by CVE-2026-5186?
CVE-2026-5186 affects Nothings stb_image.h versions up to and including 2.30.
What type of vulnerability is CVE-2026-5186?
CVE-2026-5186 is classified as a double free vulnerability within the Multi-frame GIF File Handler.
Can CVE-2026-5186 lead to security issues?
Yes, CVE-2026-5186 can potentially lead to arbitrary code execution or application crashes due to the double free condition.