๐Ÿ” CVE Alert

CVE-2026-86515

MEDIUM 4.3

vgmstream txtp txtp_parser.c add_entry resource consumption

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource consumption. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 4b6a02dd1aff6428255db912563d77d4cb0a143e. It is advisable to implement a patch to correct this issue.

CWE CWE-400 CWE-404
Vendor n/a
Product vgmstream
Published Sep 8, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for n/a vgmstream

Be the first to know when new medium vulnerabilities affecting n/a vgmstream are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / vgmstream
r2117

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/399669 vuldb.com: https://vuldb.com/vuln/399669/cti vuldb.com: https://vuldb.com/cve/CVE-2026-86515 vuldb.com: https://vuldb.com/submit/908370 github.com: https://github.com/vgmstream/vgmstream/issues/1973 github.com: https://github.com/vgmstream/vgmstream/pull/1965 github.com: https://github.com/vgmstream/vgmstream/commit/4b6a02dd1aff6428255db912563d77d4cb0a143e github.com: https://github.com/vgmstream/vgmstream/

Credits

๐Ÿ” ni-liao (VulDB User)