CVE-2026-79515: Medium severity Nothings stb vulnerability
Published Sep 9, 2026
·Updated
An out-of-bounds read in the stbttGetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.
Affected Software
1 affected component
Nothings stb
Event History
Sep 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What must an attacker be able to do to trigger the issue?
An attacker needs to supply a crafted TTF file to an affected application. The CVSS vector indicates network attack access is possible without privileges, but user interaction is required.
2
Which environments are most exposed?
Applications using the affected nothings stb commit 31c1ad3 are exposed when they process TTF files that an attacker can provide. The reported impact is denial of service; no confidentiality or integrity impact is listed.