{"id":"CVE-2026-22189","summary":"Panda3D \u003c= 1.10.16 egg-mkfont Stack Buffer Overflow","details":"The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input. When constructing glyph filenames, egg-mkfont formats a user-supplied glyph pattern (-gp) into a fixed-size stack buffer without length validation. Supplying an excessively long glyph pattern string can overflow the stack buffer, resulting in memory corruption and a deterministic crash. Depending on build configuration and execution environment, the overflow may also be exploitable for arbitrary code execution.","modified":"2026-08-12T03:51:46.521927514Z","published":"2026-01-07T20:25:37.702Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22189.json"},"references":[{"type":"WEB","url":"https://www.panda3d.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22189.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22189"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/panda3d-egg-mkfont-stack-buffer-overflow"},{"type":"PACKAGE","url":"https://github.com/panda3d/panda3d"},{"type":"EVIDENCE","url":"https://seclists.org/fulldisclosure/2026/Jan/10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/panda3d/panda3d","events":[{"introduced":"0"},{"last_affected":"e560eb8da370d86b096d6cb65eafd9ab40879b9a"}],"database_specific":{"cpe":"cpe:2.3:a:cmu:panda3d:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.10.16"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["v1.10.16","v1.10.15","v1.10.14","v1.10.13","v1.10.12","v1.10.11","v1.10.10","v1.10.9","v1.10.8","v1.10.7","v1.10.6","v1.10.5","v1.10.4.1","v1.10.4","v1.10.3","v1.10.2","v1.10.1","v1.10.0","v1.9.0","v1.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22189.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}