CVE-2026-5315 identifies an out-of-bounds read vulnerability in Nothings stb library, specifically within the stbtt__buf_get8 function of the TTF File Handler component, affecting versions up to 1.26. Rated as medium severity (CVSS 4.3), this vulnerability can be exploited remotely with low complexity, requiring user interaction, and could lead to a denial of service. Although the exploit has been publicly disclosed and the CVE is on the "Hot List: Active," there are currently no readily available exploit tools (e.g., Metasploit, Nuclei) or evidence of widespread active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.26CPE matchmatch criteria | cpe:2.3:a:nothings:stb_truetype.h:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.