{"id":"CVE-2026-22190","summary":"Panda3D \u003c= 1.10.16 egg-mkfont Format String Information Disclosure","details":"The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerability. The -gp (glyph pattern) command-line option is used directly as the format string for sprintf() with only a single argument supplied. If an attacker provides additional format specifiers, egg-mkfont may read unintended stack values and write the formatted output into generated .egg and .png files, resulting in disclosure of stack-resident memory and pointer values.","modified":"2026-08-12T03:51:34.000229514Z","published":"2026-01-07T20:25:56.205Z","database_specific":{"cwe_ids":["CWE-134"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22190.json","cna_assigner":"VulnCheck"},"references":[{"type":"WEB","url":"https://www.panda3d.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22190.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22190"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/panda3d-egg-mkfont-format-string-information-disclosure"},{"type":"PACKAGE","url":"https://github.com/panda3d/panda3d"},{"type":"EVIDENCE","url":"https://seclists.org/fulldisclosure/2026/Jan/11"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/panda3d/panda3d","events":[{"introduced":"0"},{"last_affected":"e560eb8da370d86b096d6cb65eafd9ab40879b9a"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:cmu:panda3d:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.10.16"}]}}],"versions":["v1.10.16","v1.10.15","v1.10.14","v1.10.13","v1.10.12","v1.10.11","v1.10.10","v1.10.9","v1.10.8","v1.10.7","v1.10.6","v1.10.5","v1.10.4.1","v1.10.4","v1.10.3","v1.10.2","v1.10.1","v1.10.0","v1.9.0","v1.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22190.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}