LiveActive security incident?Get immediate response
CVE Record

CVE-2026-32837: mackron / miniaudio Out-of-Bounds Read in BEXT Coding History Parsing

miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted WAV files. Attackers can exploit improper null-termination handling in the coding history field to cause out-of-bounds reads past the allocated metadata pool, resulting in application crashes or denial of service.

MediumCVSS 5.1Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2026-32837 is a crash risk in miniaudio's WAV metadata handling. A malicious WAV file can make software using vulnerable miniaudio read past allocated memory while parsing BEXT coding history metadata. The documented impact is application denial of service, not data theft or code execution.

Executive priority

Treat as moderate priority. The main business risk is service disruption in software that processes untrusted WAV files. Prioritize public upload paths, automated media pipelines, and bundled desktop or embedded products using miniaudio.

Technical view

miniaudio 0.11.25 and earlier contain a heap out-of-bounds read in WAV BEXT coding history parsing caused by improper null-termination handling, mapped to CWE-170. Processing crafted WAV metadata can read beyond the metadata pool and trigger memory access violations. The bundle cites fixes in miniaudio commit 1df46ae and related dr_libs commit 04e40d66.

Likely exposure

Exposure is most likely in applications, media services, games, embedded products, or content pipelines that use miniaudio and process WAV files from users, partners, or automated feeds. Products with no WAV ingestion or only trusted local files have lower practical exposure.

Exploitation context

The source bundle does not show active exploitation, and KEV is false. Exploitation requires a vulnerable application to process a crafted WAV file with malformed BEXT coding history metadata. Reported impact is crash or denial of service; stronger impacts are not evidenced here.

Researcher notes

The evidence identifies miniaudio 0.11.25 and earlier and a heap out-of-bounds read in BEXT coding history parsing. The CVSS 4.0 score is 5.1. Available sources support denial of service only; avoid claiming remote code execution or active exploitation without new evidence.

Mitigation direction

  • Inventory products and services that bundle or link miniaudio.
  • Update miniaudio to a version containing commit 1df46ae or later vendor release.
  • Review dr_libs dependency guidance where dr_wav is separately embedded.
  • Restrict untrusted WAV ingestion until affected components are updated.
  • Monitor upstream miniaudio and VulnCheck guidance for release-specific fixes.

Validation and detection

  • Check dependency manifests, vendored headers, and build artifacts for miniaudio versions.
  • Confirm whether exposed workflows parse WAV BEXT metadata from untrusted files.
  • Verify the deployed code includes miniaudio commit 1df46ae or equivalent fix.
  • Run regression tests for WAV metadata parsing after updating.
  • Review crash telemetry for WAV parsing faults in affected applications.
Prepared
Confidence
high
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-170: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-32837 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.1 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
1ADP providers
5Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: partial

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.1CVSS 4.0MediumCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:NVulnCheck
4CVSS 3.1MediumCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L2.51.4VulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

5.1Medium
CVSS 4.0 vector shape for CVE-2026-32837Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
mackronminiaudio0, 1df46ae9a0eed5aa9f58b179d2cc4af5d23f8bdeunknown
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.