High severity7.8NVD Advisory· Published Feb 8, 2021· Updated Jun 17, 2026
CVE-2021-26826
CVE-2021-26826
Description
A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:godotengine:godot_engine:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:godotengine:godot_engine:*:*:*:*:*:*:*:*range: <=3.2
- (no CPE)range: <=3.2
- Godot Engine/Godot Enginedescription
- Range: <=3.2
- osv-coords2 versionspkg:rpm/opensuse/godot&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/godot3&distro=openSUSE%20Tumbleweed
< 3.3.3-1.3+ 1 more
- (no CPE)range: < 3.3.3-1.3
- (no CPE)range: < 3.5.1-1.1
Patches
Vulnerability mechanics
References
2- github.com/godotengine/godot/pull/45701nvdPatchThird Party Advisory
- github.com/godotengine/godot/pull/45701/commits/403e4fd08b0b212e96f53d926e6273e0745eaa5anvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.