Vulnerabilities
- Panda3D <= 1.10.16 egg-mkfont format string information disclosure CVE-2026-22190
CVE ID : CVE-2026-22190 Published : Jan. 7, 2026, 9:16 p.m. | 1 hour, 13 minutes ago Description : Panda3D versions up to and including 1.10.16 egg-mkfont contains an uncontrolled format string vulnerability. The -gp (glyph pattern) command-line option is used directly as the format string for sprintf() with only a single argument supplied. If an attacker provides additional format specifiers, egg-mkfont may read unintended stack values and write the formatted output into generated .egg and .png files, resulting in disclosure of stack-resident memory and pointer values. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Source: Telegram CVE Monitor