{"id":"CVE-2026-86514","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-86514","summary":"A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based…","details":"A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 4669d37a6af94866f6f0628678f9f90d46954e8b. To fix this issue, it is recommended to deploy a patch.","published":"2026-09-08T03:17:19.790","modified":"2026-09-08T03:17:19.790","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b","label":"vgmstream/vgmstream@4669d37"},"references":[{"type":"WEB","url":"https://github.com/vgmstream/vgmstream/"},{"type":"WEB","url":"https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b"},{"type":"WEB","url":"https://github.com/vgmstream/vgmstream/issues/1972"},{"type":"WEB","url":"https://github.com/vgmstream/vgmstream/pull/1956"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-86514"},{"type":"WEB","url":"https://vuldb.com/submit/908369"},{"type":"WEB","url":"https://vuldb.com/vuln/399668"},{"type":"WEB","url":"https://vuldb.com/vuln/399668/cti"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-08T03:17:19.790"}}