CVE-2026-32836

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
17/03/2026
Last modified:
20/03/2026

Description

dr_libs dr_flac.h version 0.13.3 and earlier contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:* 0.13.3 (including)