CVE-2026-88365: Integer Overflow
Published Sep 24, 2026
·Updated
minimp3 commit ea99364f contains an integer overflow vulnerability in mp3decskipid3v1() when parsing the APEv2 tag-size field.
Affected Software
1 affected component
minimp3=ea99364f
Event History
Sep 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:17 PM
Description
Frequently Asked Questions
1
How can I determine whether my integration is affected?
Check whether the minimp3 source in use includes commit ea99364f. The available information does not identify a patched version or a remediation commit.