CVE-2026-5317HIGH 8.8EPSS p33.9%

CVE-2026-5317CVE-2026-5317

Description

A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.43% probability of exploitation · percentile 33.9% · 2026-06-19T12:03:05Z
Published2026-04-02
Last modified2026-04-30

Underlying weaknesses· 2

CWE-119CWE-787

References

  1. https://gist.github.com/d0razi/2ff8a0e812f74dd6fe7f2843931bb90c
  2. https://vuldb.com/submit/780561
  3. https://vuldb.com/vuln/354649
  4. https://vuldb.com/vuln/354649/cti

2

TypeTargetConfidenceTier
WeaknessImproper Restriction of Operations within the Bounds of a Memory Buffercwe-1190%live
WeaknessOut-of-bounds Writecwe-7870%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-5315
CVE
CVE-2026-5314
CVE
CVE-2025-3407
CVE
CVE-2025-3408
CVE
CVE-2025-3409
CVE
CVE-2025-36937
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.