CVE-2026-86515
vgmstream txtp txtp_parser.c add_entry resource consumption
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource consumption. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 4b6a02dd1aff6428255db912563d77d4cb0a143e. It is advisable to implement a patch to correct this issue.
| CWE | CWE-400 CWE-404 |
| Vendor | n/a |
| Product | vgmstream |
| Published | Sep 8, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a vgmstream
Be the first to know when new medium vulnerabilities affecting n/a vgmstream are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / vgmstream
r2117
References
vuldb.com: https://vuldb.com/vuln/399669 vuldb.com: https://vuldb.com/vuln/399669/cti vuldb.com: https://vuldb.com/cve/CVE-2026-86515 vuldb.com: https://vuldb.com/submit/908370 github.com: https://github.com/vgmstream/vgmstream/issues/1973 github.com: https://github.com/vgmstream/vgmstream/pull/1965 github.com: https://github.com/vgmstream/vgmstream/commit/4b6a02dd1aff6428255db912563d77d4cb0a143e github.com: https://github.com/vgmstream/vgmstream/
Credits
๐ ni-liao (VulDB User)