PT-2026-2164 · Panda3D · Panda3D

Ron Edgerson

·

Published

2026-01-07

·

Updated

2026-05-26

·

CVE-2026-22190

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Panda3D versions up to and including 1.10.16
Description Panda3D’s egg-mkfont utility contains an uncontrolled format string issue. The -gp command-line option is directly used as the format string for the sprintf() function with a single argument. Providing additional format specifiers by an attacker may lead to the reading of unintended stack values and writing the formatted output into generated .egg and .png files, potentially disclosing stack-resident memory and pointer values.
Recommendations Versions prior to 1.10.16 are not affected. Update Panda3D to a version later than 1.10.16.

Exploit

Fix

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

CVE-2026-22190

Affected Products

Panda3D