Two high-severity vulnerabilities were disclosed in widely used file-parsing libraries, allowing crafted media files to trigger memory-safety failures during parsing. In cgltf <= 1.15, CVE-2026-32845 stems from an integer overflow in cgltf_validate() while checking sparse accessors in malicious glTF or GLB files. The unchecked arithmetic can lead to heap buffer over-reads in cgltf_calc_index_bound(), causing crashes and potentially exposing process memory.
A separate flaw, CVE-2026-40494, affects the SAIL image loading and saving library’s TGA RLE decoder in tga.c. The bug is a heap-based buffer overflow caused by missing bounds checks on the raw-packet path, while the run-packet path correctly clamps writes; attackers can use a crafted TGA file to write up to 496 bytes of controlled data past the end of a heap buffer. The issue affects versions before commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302 and carries a critical CVSS:3.1 rating due to potential confidentiality, integrity, and availability impact.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A heap-based buffer overflow in SAIL's TGA RLE decoder was received by GitHub Security Advisories, describing a missing bounds check in the raw-packet path that can allow controlled heap out-of-bounds writes. The disclosure noted that versions before commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302 are affected and that the referenced commit patches the flaw.
A high-severity integer overflow vulnerability affecting cgltf 1.15 and earlier was documented, involving unchecked arithmetic in cgltf_validate() that can lead to heap buffer over-reads in cgltf_calc_index_bound() via crafted glTF or GLB files. The issue was referenced through a GitHub issue and a VulnCheck advisory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.