CVE-2026-32837
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
17/03/2026
Last modified:
19/03/2026
Description
miniaudio version 0.11.25 and earlier contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted WAV files. Attackers can exploit improper null-termination handling in the coding history field to cause out-of-bounds reads past the allocated metadata pool, resulting in application crashes or denial of service.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mackron:miniaudio:*:*:*:*:*:*:*:* | 0.11.25 (including) |
To consult the complete list of CPE names with products and versions, see this page



