The Stb Project maintains a single, widely embedded image-processing library that despite its narrow product scope has substantial reach across graphics applications, game engines, and multimedia software through dependency chains. Vulnerabilities affecting this library center on memory-safety issues including out-of-bounds writes and reads, as well as calculation errors, which are characteristic of C-based image codec and decoding logic. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stb Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15058CRITICAL stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service. | Aug 14, 2019 | 9.1 | 30 | NO | NO |
CVE-2022-28048HIGH STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac. | Apr 15, 2022 | 8.8 | 29 | NO | NO |
CVE-2021-37789HIGH stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service. | Nov 2, 2022 | 8.1 | 26 | NO | NO |
CVE-2021-28021HIGH Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file. | Oct 15, 2021 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stb Project.
Media articles that mention a CVE ID that affects a product developed by Stb Project — matched by CVE ID, not by vendor name.