Stb · Stb · CVE-2026-102805
**Name of the Vulnerable Software and Affected Versions**
Nothings stb versions prior to 1.17
**Description**
A flaw in the Image Encoding component of the `stb image write.h` library allows for a remote attack. The issue resides in the `stbi write png to mem()`, `stbi write jpg core()`, and `stbi write tga core()` functions, where a manipulation can lead to an integer overflow, a condition where an arithmetic operation results in a value that exceeds the storage capacity of the integer type.
**Recommendations**
Update Nothings stb to version 1.17 or later.
As a temporary workaround, restrict the use of the `stbi write png to mem()`, `stbi write jpg core()`, and `stbi write tga core()` functions.