PT-2026-27144 · Jkuhlmann · Cgltf

Ana Kapulica

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32845

CVSS v4.0

6.9

Medium

AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supplying crafted glTF/GLB input files with attacker-controlled size values. Attackers can exploit unchecked arithmetic operations in sparse accessor validation to cause heap buffer over-reads in cgltf calc index bound(), resulting in denial of service crashes and potential memory disclosure.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-32845

Affected Products

Cgltf