CVE-2026-79515

MEDIUM CVSS 3.1: 4.3 EPSS 0.18%
Updated Sep 10, 2026
An
Parameter Value
CVSS 4.3 (MEDIUM)
Vendor An
Public PoC No

An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1