CVE-2026-32837Disclosure(mackron / miniaudio)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted WAV files. Attackers can exploit improper null-termination handling in the coding history field to cause out-of-bounds reads past the allocated metadata pool, resulting in application crashes or denial of service.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-170

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • miniaudio

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
miniaudio

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-17: 2Technical Details · 2026-03-17: 203-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32837 Heap Out-of-Bounds Read Vulnerability in miniaudio WAV BEXT Metad... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32837 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-32837, a heap out‑of‑bounds read issue in miniaudio WAV BEXT metadata, and directs readers to a Vulmon page for further details.

    0000041
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32837 miniaudio version 0.11.25 and earlier contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access v… https://www.cve.org/CVERecord?id=CVE-2026-32837

    Post summary

    The note announces a heap out‑of‑bounds read vulnerability in miniaudio’s WAV BEXT metadata parser (CVE‑2026‑32837) and links to the official CVE record.

    0000076
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmackronminiaudio---

Explore more