What is CVE-2026-75148?
CVE-2026-75148 is an integer overflow vulnerability in the non-sparse accessor bounds check within `cgltf_validate()` in cgltf through version 1.15. A remote attacker can exploit this flaw by providing malformed .gltf or .glb input with crafted accessor count values, potentially leading to memory disclosure and denial of service. It is strongly recommended to update the cgltf library to the latest patched version.
Azərbaycanca: CVE-2026-75148, cgltf kitabxanasının 1.15 versiyasına qədər olan versiyalarında `cgltf_validate()` funksiyasındakı non-sparse accessor sərhəd yoxlamasında tam ədəd daşması zəifliyidir. Uzaqdan hücum edən şəxs xüsusi hazırlanmış .gltf və ya .glb faylları vasitəsilə bu boşluqdan istifadə edərək yaddaş məlumatlarının ifşasına və xidmət rəddinə səbəb ola bilər. Bu zəifliyin təsirini azaltmaq üçün cgltf kitabxanasını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
How can CVE-2026-75148 be exploited?
A remote attacker can exploit it by providing malformed .gltf or .glb input to trigger the integer overflow in the `cgltf_validate()` function.
Which versions of cgltf are affected by CVE-2026-75148?
The vulnerability affects cgltf through version 1.15.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.