cvedb.io
CVE-2026-22188
MEDIUM · CVSS 5.5
EPSS exploitation probability: 0%
Published 2026-01-07T21:16:02.747 · Last modified 2026-06-17T10:19:30.600

Summary

The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based directly on the attacker-controlled argc value without validation. Supplying a large number of command-line arguments can exhaust stack space and propagate uninitialized stack memory into Python interpreter initialization, resulting in a reliable crash and undefined behavior.

Affected products

cmu — panda3d

Does this affect you?

Add your gear to cvedb and we'll alert you only when cmu ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.