HIGHVulnerability
CVE-2026-71266
tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplicated in a second function in the same file.
Properties
- severity
- HIGH
- score
- 7.8
- cve_id
- CVE-2026-71266
- vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- published_at
- 2026-08-05T13:24:50.843
- last_modified
- 2026-08-26T17:13:24.800
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Stack-based Buffer Overflow
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph