CVE-2026-32845Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supplying crafted glTF/GLB input files with attacker-controlled size values. Attackers can exploit unchecked arithmetic operations in sparse accessor validation to cause heap buffer over-reads in cgltf_calc_index_bound(), resulting in denial of service crashes and potential memory disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-23: 3Technical Details · 2026-03-23: 203-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-32845 - jkuhlmann - cgltf - https://www.redpacketsecurity.com/cve-alert-cve-2026-32845-jkuhlmann-cgltf/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32845 #jkuhlmann #cgltf

    Post summary

    A CVE alert post announces the existence of CVE-2026-32845 affecting cgltf, citing author jkuhlmann, and directs readers to a link for additional information.

    01000127
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32845 Integer Overflow Vulnerability in cgltf 1.15 Enables Heap Buffer ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32845 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A tweet announces CVE-2026-32845, an integer overflow that enables a heap buffer overflow in cgltf 1.15, and points to Vulmon for details, but provides no PoC, exploit, or patch information.

    0000052
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32845 - High cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads b... https://www.thehackerwire.com/vulnerability/CVE-2026-32845/ https://t.co/Bzemohdbt0

    Post summary

    The tweet announces CVE-2026-32845, highlighting an integer overflow that causes out‑of‑bounds reads in cgltf 1.15 and earlier, with no mention of active exploitation, patches, or PoC code.

    0000033
    145 followersView on X

Explore more