CVE-2026-5313: Nothings stb GIF Decoder stb_image.h stbi__gif_load_next denial of service
A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbigifloadnext in the library stbimage.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5313?
CVE-2026-5313 is classified as a denial of service vulnerability.
How do I fix CVE-2026-5313?
To fix CVE-2026-5313, upgrade Nothings stb_image.h to version 2.31 or later.
What component is affected by CVE-2026-5313?
CVE-2026-5313 affects the GIF Decoder function stbi__gif_load_next in the stb_image.h library.
What versions of Nothings stb_image.h are vulnerable to CVE-2026-5313?
Versions of Nothings stb_image.h up to and including 2.30 are vulnerable to CVE-2026-5313.
What type of attack does CVE-2026-5313 facilitate?
CVE-2026-5313 facilitates denial of service attacks through manipulation of the GIF Decoder.