Junglewise Threat Intelligence

CVE-2026-86515: vgmstream resource consumption in txtp parser

CVE-2026-86515 · Severity: medium · CVSS 4.3 · Published 2026-09-08

Technologies: Vgmstream. Vendors: Vgmstream.

Executive brief

vgmstream is a library used to playback audio formats from video games. An attacker can craft a malicious txtp (playlist-like) file that manipulates the range_start and range_end arguments to consume excessive system resources, potentially causing a denial of service.

Technical details

The vulnerability exists in the add_entry function of src/meta/txtp_parser.c in vgmstream up to revision r2117. Improper validation of the range_start and range_end arguments allows an attacker to trigger uncontrolled resource consumption. The attack vector is remote—a victim can be exploited by opening a malicious .txtp file. The vulnerability has been publicly disclosed and a patch is available (commit 4b6a02dd1aff6428255db912563d77d4cb0a143e). No authentication or special privileges are required to trigger the issue.

Affected products

  • vgmstream vgmstream up to r2117

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Patch commit 4b6a02dd1aff6428255db912563d77d4cb0a143e

References

Related threats