PT-2026-22515 · Jarikomppa · Soloud

Oneafter

·

Published

2026-03-01

·

Updated

2026-03-13

·

CVE-2026-3393

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jarikomppa soloud versions prior to 20200208
Description A heap-based buffer overflow exists in the SoLoud::Wav::loadflac function within the src/audiosource/wav/soloud wav.cpp file of the Audio File Handler component. This issue affects the processing of FLAC files. The exploit has been publicly disclosed and may be used for malicious purposes. The issue was reported to the project developers, but no response has been received. The attack requires local access.
Recommendations Versions prior to 20200208 should be updated. As a temporary workaround, consider restricting access to FLAC file handling or disabling the SoLoud::Wav::loadflac function until a patch is available.

Exploit

Fix

Buffer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-3393

Affected Products

Soloud