CVE-2026-79516
Deferred Deferred - Pending Action

Out-of-Bounds Read in stb_sprintf Library

Vulnerability report for CVE-2026-79516, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: MITRE

Description

An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nothings stb *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in the stbsp_vsnprintf function within the stb_sprintf.h library. It occurs when the function processes a specially crafted input, causing it to read memory outside its intended bounds. This can lead to a Denial of Service (DoS) condition by crashing the application or causing unexpected behavior.

Detection Guidance

This vulnerability involves an out-of-bounds read in the stbsp_vsnprintf function. Detection requires analyzing code that uses the stb library for improper string formatting. Check for applications using stb_sprintf.h and review input handling in functions like stbsp_vsnprintf. No direct network detection commands are available due to the nature of the flaw.

Impact Analysis

The vulnerability may allow attackers to disrupt the normal operation of applications using the affected stb_sprintf.h library. This could result in crashes, data corruption, or service unavailability, particularly if the application processes untrusted input.

Compliance Impact

This vulnerability causes a Denial of Service (DoS) via out-of-bounds read, which may disrupt system availability. For GDPR, availability is a key principle, so prolonged DoS could impact compliance. HIPAA also requires availability of protected health information systems, so similar risks apply.

Mitigation Strategies

Update the stb library to a version that fixes the out-of-bounds read in stbsp_vsnprintf. If using a project that includes stb, check for patches or newer commits addressing this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79516. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart