Description
OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.
Published: 2026-10-03
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption (Potential RCE)
Action: Apply Patch
AI Analysis

Impact

OpenAPV versions prior to 1.1.1.0 contain a heap-based buffer overflow in the read_bitstream routine, which can corrupt memory if an attacker supplies a crafted bitstream. This weakness is classified as CWE-190, another name for integer overflow or wraparound, leading to potential arbitrary code execution or denial of service depending on how the corrupted data is handled.

Affected Systems

Vulnerable instances of the OpenAPV tool released by the Academy Software Foundation. All releases before 1.1.1.0 are affected; the recommended safe releases are v1.1.1.0 or newer.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity, and no EPSS score is currently available, suggesting limited knowledge about exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via unsanitized user input that triggers the read_bitstream routine, either locally or from a remote source if the tool processes network data.

Generated by OpenCVE AI on October 3, 2026 at 03:52 UTC.

Remediation

Vendor Solution

Update to OpenAPV v1.1.1.0 https://github.com/AcademySoftwareFoundation/openapv/releases/tag/v1.1.1.0  or newer


OpenCVE Recommended Actions

  • Upgrade OpenAPV to version 1.1.1.0 or newer as provided by the Academy Software Foundation
  • Restrict OpenAPV input to trusted sources or implement input validation to prevent malicious bitstreams
  • If upgrade is not possible, run OpenAPV in a sandboxed environment or container with limited privileges to contain potential memory corruption

Generated by OpenCVE AI on October 3, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
Title Heap-based Buffer Overflow in OpenAPV read_bitstream

Sat, 03 Oct 2026 01:15:00 +0000


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-03T01:06:56.610Z

Reserved: 2026-08-25T06:09:47.545Z

Link: CVE-2026-79113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T01:17:25.287

Modified: 2026-10-03T01:17:25.287

Link: CVE-2026-79113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T04:00:12Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound