CVE-2026-102804 Details
Description
A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
An integer overflow vulnerability has been identified in the Nothings stb library, specifically in the hexwave_init function of stb_hexwave.h. This vulnerability arises from improper handling of the width and oversample parameters, which can be manipulated to cause an overflow. The issue has been made public and can be exploited remotely.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nothings/stb/ | [email protected] | Vendor |
| https://github.com/nothings/stb/issues/1961 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/user-attachments/files/31351618/poc_hexwave.c | [email protected] | Broken LinkExploit |
| https://vuldb.com/cve/CVE-2026-102804 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/944861 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411496 | [email protected] | Content Wall |
| https://vuldb.com/vuln/411496/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-189 | Numeric Errors | [email protected] |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Nothings stb_hexwave | <= 2c980bb59875b0d32144a71867fbdebb2f77cd20 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion