PT-2026-27144 · Cgltf · Cgltf
Ana Kapulica
·
Published
2026-03-23
·
Updated
2026-05-01
·
CVE-2026-32845
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cgltf versions prior to 1.15
Description
cgltf versions prior to 1.15 contain an integer overflow issue in the
cgltf validate() function when validating sparse accessors. This allows attackers to trigger out-of-bounds reads by providing specially crafted glTF/GLB input files with attacker-controlled size values. Unchecked arithmetic operations in sparse accessor validation can cause heap buffer over-reads in the cgltf calc index bound() function, potentially leading to denial of service and memory disclosure.Recommendations
Update to a version newer than 1.15.
Exploit
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cgltf