{"id":"CVE-2026-18497","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-18497","summary":"A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT()…","details":"A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed TTF (TrueType Font) files. The vulnerability resides in the glyph data parsing path.\r\n\r\nAn attacker can craft a malformed TTF file with an inflated endPtsOfContours value and truncate the remaining glyph data. When an application utilizing stb_truetype.h (such as various game engines or graphics software) attempts to load, bake, or render this malformed font via stbtt_GetGlyphShape(), the parser will attempt to read past the end of the glyph data buffer, triggering the out-of-bounds read.","published":"2026-08-07T15:16:59.707","modified":"2026-08-12T14:17:48.027","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/122.html"},{"type":"WEB","url":"https://github.com/nothings/stb"},{"type":"WEB","url":"https://github.com/nothings/stb/issues/1905"},{"type":"WEB","url":"https://kb.cert.org/vuls/id/987105"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/987105"},{"type":"WEB","url":"https://github.com/nothings/stb/issues/1905"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T14:17:48.027"}}