Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 12 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cmu
Cmu panda3d |
|
| Weaknesses | CWE-908 | |
| CPEs | cpe:2.3:a:cmu:panda3d:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cmu
Cmu panda3d |
|
| Metrics |
cvssV3_1
|
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Panda3d
Panda3d panda3d |
|
| Vendors & Products |
Panda3d
Panda3d panda3d |
Wed, 07 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Jan 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Panda3D versions up to and including 1.10.16 deploy-stub contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based directly on the attacker-controlled argc value without validation. Supplying a large number of command-line arguments can exhaust stack space and propagate uninitialized stack memory into Python interpreter initialization, resulting in a reliable crash and undefined behavior. | |
| Title | Panda3D <= 1.10.16 Deploy-Stub Stack Exhaustion via Unbounded alloca() | |
| Weaknesses | CWE-457 CWE-789 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T01:30:09.033Z
Reserved: 2026-01-06T16:47:17.183Z
Link: CVE-2026-22188
Updated: 2026-01-07T21:23:10.082Z
Status : Analyzed
Published: 2026-01-07T21:16:02.747
Modified: 2026-01-12T18:00:28.637
Link: CVE-2026-22188
No data.
OpenCVE Enrichment
Updated: 2026-04-16T18:30:10Z