Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32836

24
FAUCET Score

CVE-2026-32836 describes an uncontrolled memory allocation vulnerability in mackron dr_libs dr_flac.h versions 0.13.3 and earlier, specifically within the drflac__read_and_decode_metadata() function. This flaw allows attackers to trigger excessive memory allocation by supplying crafted FLAC streams containing malicious PICTURE metadata blocks. Exploitation, which is a local attack requiring low privileges and no user interaction, can lead to a denial of service through memory exhaustion, reflected by a CVSS score of 5.5 (Medium). There is currently no evidence of active exploitation, nor is the vulnerability listed on CISA's KEV catalog or Hot List. No public exploit code is available, and there is no community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.13.3CPE matchmatch criteria
cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
8.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 17th percentile among its peer group of 3,050 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryworkaround availablevia nvd_reference
View patch

References

github.com / mackron/dr_libs/commit/4f5a4cd3b57564d969443c580c75857e039f100a
github.com / mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676
github.com / mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8
github.com / mackron/dr_libs/issues/298
ExploitIssue TrackingMitigationVendor Advisory
vulncheck.com / advisories/mackron-dr-libs-excessive-memory-allocation-in-picture-metadata-parsing
Third Party Advisory