HIGH
Sean Barrett (nothings)
CVE published 2026-08-07
CVE-2026-18497
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, used for parsing TrueType font files. The vulnerability is in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed TTF (TrueType Font) files. This can lead to potential crashes or exploitation if an attacker crafts a malformed TTF file with an inflated en [truncated]