← Back to CVE List
CVE-2026-93331NVD
Vulnerability Summary
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. The affected component should be upgraded.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 7.3 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- n/a GPAC >= 26.08-DEV
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/406641
- https://vuldb.com/vuln/406641/cti
- https://vuldb.com/cve/CVE-2026-93331
- https://vuldb.com/submit/942834
- https://github.com/gpac/gpac/issues/3868
- https://github.com/gpac/gpac/commit/6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68
- https://github.com/gpac/gpac/releases/tag/abi-16.26
- https://github.com/gpac/gpac/