Description
An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An out-of-bounds read occurs in the gf_dm_get_chunk_data function of the external actor to send a crafted HTTP request that triggers a denial of service. The flaw is identified as CWE-125, a buffer overread that can interrupt the GPAC process. No privilege escalation or data exposure is required; the consequence is service interruption.

Affected Systems

GPAC version 26.07.0, including any installations or deployments that use the downloader component without the upstream fix. The issue exists only in this release and is not tied to a commercial vendor; the open‑source project must apply the patch.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% signals a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely over the network by sending a specially crafted HTTP request to the GPAC instance; no additional conditions or elevated privileges are required.

Generated by OpenCVE AI on September 11, 2026 at 04:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GPAC to a version that includes the commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640 or apply the upstream patch to the source code.
  • If the downloader component is not required, disable or restrict HTTP chunked content handling to prevent exploitation.
  • Add monitoring and rate‑limiting of incoming HTTP traffic to detect and mitigate repeated DoS attempts.

Generated by OpenCVE AI on September 11, 2026 at 04:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gpac:gpac:26.07.0:*:*:*:*:*:*:*

Fri, 11 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title GPAC Downloader Out-of-Bounds Read Allows DoS via HTTP

Fri, 11 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in GPAC Downloader Causes Denial of Service via Crafted HTTP Requests
Weaknesses CWE-119

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Gpac
Gpac gpac
Vendors & Products Gpac
Gpac gpac

Wed, 09 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in GPAC Downloader Causes Denial of Service via Crafted HTTP Requests
Weaknesses CWE-119

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:R'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-10T18:58:16.891Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79522

cve-icon Vulnrichment

Updated: 2026-09-10T18:58:11.275Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T21:17:04.683

Modified: 2026-09-15T17:01:40.510

Link: CVE-2026-79522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:00:13Z

Weaknesses