Impact
An out-of-bounds read occurs in the gf_dm_get_chunk_data function of the external actor to send a crafted HTTP request that triggers a denial of service. The flaw is identified as CWE-125, a buffer overread that can interrupt the GPAC process. No privilege escalation or data exposure is required; the consequence is service interruption.
Affected Systems
GPAC version 26.07.0, including any installations or deployments that use the downloader component without the upstream fix. The issue exists only in this release and is not tied to a commercial vendor; the open‑source project must apply the patch.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% signals a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely over the network by sending a specially crafted HTTP request to the GPAC instance; no additional conditions or elevated privileges are required.
OpenCVE Enrichment