A vulnerability in cgltf through 1.15 allows remote attackers to cause memory disclosure and denial of service via crafted accessor count values. This issue arises from an integer overflow in the non-sparse accessor bounds check within cgltf_validate(). The vulnerability can be triggered by providing malformed .gltf or .glb input with a specially crafted accessor count to overflow the unsigned integer mul [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-23T16:16:48.583Z and has not been modified since then. The NVD entry is currently Deferred. This integer overflow vulnerability in cgltf's cgltf_validate() function allows attackers to trigger out-of-bounds reads via crafted glTF/GLB input files, potentially causing denial of service crashes and mem [truncated]