CVE-2026-102804: medium-severity vulnerability in Nothings stb
Nothings stb stb_hexwave.h hexwave_init integer overflow
Published · Updated
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 0.3%
exploitation probability
0.3%top 74% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
Nothings · stbpublic PoCs found — 1
cve_referencegithub.com/user-attachments/files/31351618/poc_hexwave.cunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Nothings stb
In the same product, most dangerous first.
CVE-2026-5315MEDIUMNothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-boundsEPSS 0.8%CVE-2026-5314MEDIUMNothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-boundsEPSS 0.8%CVE-2026-5316MEDIUMNothings stb stb_vorbis.c setup_free allocation of resourcesEPSS 0.7%CVE-2026-5317MEDIUMNothings stb stb_vorbis.c start_decoder out-of-bounds writeEPSS 0.6%CVE-2025-3406MEDIUMNothings stb Header Array stbhw_build_tileset_from_image out-of-boundsEPSS 0.6%CVE-2025-3409MEDIUMNothings stb stb_include_string stack-based overflowEPSS 0.5%