PatchSiren

vgmstream CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW vgmstream CVE published 2026-09-08

CVE-2026-86515

A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource consumption. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 4b6a02dd1aff6428255db912563d77d4cb0a [truncated]

LOW vgmstream CVE published 2026-09-08

CVE-2026-86514

A weakness has been identified in vgmstream up to r2117, specifically in the function sscanf of the file src/meta/txth.c of the component txth-txtp, which can cause a stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. To fix this issue, it is recommended to deploy a patch named 4669d37a6af94866f6f [truncated]