CVE-2026-92475 Details
Description
A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. Upgrading to version abi-16.26 will fix this issue. Patch name: c74a3065038ede35c1c7b75fa493a69ef6bcdb84. It is recommended to upgrade the affected component.
A vulnerability allowing out-of-bounds read has been identified in GPAC version 26.08-DEV. The issue arises in the function 'wait_for_header_and_parse' within 'src/utils/downloader.c', where the 'Content-Range' header is processed. This vulnerability requires local access and can be exploited by sending a crafted 'Content-Range' header that truncates the expected range, leading to a heap buffer overflow. The vulnerability has been publicly disclosed and could be exploited in the wild.
Users are advised to upgrade to GPAC version abi-16.26, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gpac/gpac/ | [email protected] | Vendor |
| https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84 | [email protected] | Source CodeVendor |
| https://github.com/gpac/gpac/issues/3859 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/gpac/gpac/releases/tag/abi-16.26 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-92475 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/941761 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/405734 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/405734/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GPAC | 26.08-DEV |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion