Description
A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.26 is able to mitigate this issue. This patch is called 37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12. Upgrading the affected component is recommended.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

A heap-based buffer overflow occurs in the rmt_client_handle_ws_frame function of GPAC's WebSocket handler when the argument payload_size is manipulated. The flaw can allow an attacker to overwrite memory on the heap, leading to arbitrary code execution or a crash, thereby compromising confidentiality, integrity, and availability. The weakness is a classic buffer overflow, classified under CWE-119 and CWE-122.

Affected Systems

GPAC (GPAC multimedia framework) version 26.07.0 is affected. The upstream patch, identified by commit 37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12, is included in release abi-16.26. Any installation running the vulnerable version should be upgraded to abi-16.26 or apply the specific commit.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate risk; the EPSS score is below 1%, meaning the probability of exploitation is currently very low. However, the vulnerability can be triggered remotely via malicious WebSocket frames, and the exploit has been publicly disclosed. The vulnerability is not currently listed in the CISA KEV catalog, but administrators should consider it in risk assessments.

Generated by OpenCVE AI on September 18, 2026 at 05:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi-16.26 or apply the fix from commit 37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12.
  • If an upgrade cannot be performed immediately, configure the WebSocket handler to enforce a maximum payload size and reject frames that exceed this limit to mitigate the overflow.
  • Enable or review application logs to detect malformed WebSocket frames that may indicate exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 05:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.26 is able to mitigate this issue. This patch is called 37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12. Upgrading the affected component is recommended.
Title GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-122
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T18:09:36.012Z

Reserved: 2026-09-16T08:47:23.171Z

Link: CVE-2026-92399

cve-icon Vulnrichment

Updated: 2026-09-18T18:09:29.248Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T17:18:19.590

Modified: 2026-09-18T18:18:08.480

Link: CVE-2026-92399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-122

    Heap-based Buffer Overflow