Floooh maintains the Sokol library, a set of cross-platform C headers for graphics and audio that operate at a systems level where memory-safety is critical to safe operation. The vulnerability profile centers on buffer-handling issues—improper bounds restrictions, out-of-bounds writes, and both heap and stack-based buffer overflows—reflecting the manual memory management inherent to a low-level systems library. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Floooh over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14958HIGH A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability affects the function _sg_pipeline_common_init in the library | Dec 19, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-15155HIGH A vulnerability was detected in floooh sokol up to 16cbcc864012898793cd2bc57f802499a264ea40. The impacted element is the function _sg_pipeline_desc_defaults in the library sokol_gf | Dec 28, 2025 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Floooh.
Media articles that mention a CVE ID that affects a product developed by Floooh — matched by CVE ID, not by vendor name.