Impact
The vulnerability is an out-of-bounds read in the gf_dm_data_received function of GPAC's downloader module. When a crafted HTTP request is processed, the function accesses memory beyond the allocated buffer, leading the application to crash. This loss of memory integrity results in a denial of service that can be triggered repeatedly by an attacker to exhaust resources and render the GPAC service unavailable.
Affected Systems
GPAC version 26.07.0 is affected. No other vendor or product variants are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, but the lack of a KEV listing suggests no current public exploitation. Attack vectors are inferred to be network‑based, as the flaw is triggered by sending a specially crafted HTTP request to the GPAC downloader. An attacker would need network access to the machine running GPAC to exploit this vulnerability.
OpenCVE Enrichment