Description
A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. Upgrading to version abi-16.26 will fix this issue. Patch name: c74a3065038ede35c1c7b75fa493a69ef6bcdb84. It is recommended to upgrade the affected component.
Published: 2026-09-16
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure through out-of-bounds read
Action: Patch
AI Analysis

Impact

The vulnerability resides in GPAC’s downloader component, where manipulating the Content-Range header during a media download triggers an out-of-bounds read in the function wait_for_header_and_parse. This flaw can allow an attacker with local access to read memory beyond the intended buffer, potentially leaking sensitive data from the process. The CVE description explicitly notes that the exploit requires local privilege and that it has been made publicly available, but the flaw does not provide a pathway to execute code or affect remote systems.

Affected Systems

Affected versions include GPAC 26.08‑DEV. The recommended fix is to upgrade to the abi‑16.26 release or any later build that incorporates commit c74a3065038ede35c1c7b75fa493a69ef6bcdb84. No other vendor or product versions are listed, and the fix is specific to GPAC’s upstream repository.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate impact, while the EPSS score of less than 1 % reflects a very low likelihood of exploitation in the wild. The vulnerability is not catalogued in CISA’s KEV, further suggesting limited exploitation activity. Because the attack requires local access, a threat actor must first gain the ability to run GPAC on the target machine, after which the manipulated Content-Range header can drive the out‑of‑bounds read.

Generated by OpenCVE AI on September 18, 2026 at 05:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi‑16.26 or later, which contains commit c74a3065038ede35c1c7b75fa493a69ef6bcdb84. This is the first priority mitigation step that fully patches the flaw.
  • If an immediate upgrade is not possible, restrict local execution of the GPAC binary to trusted users and disable or monitor any automated download mechanisms that could be used to craft malicious Content‑Range headers.
  • Continuously monitor GPAC log output or other system logs for suspicious Content‑Range requests or abnormal memory access attempts, and investigate any such events promptly.

Generated by OpenCVE AI on September 18, 2026 at 05:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. Upgrading to version abi-16.26 will fix this issue. Patch name: c74a3065038ede35c1c7b75fa493a69ef6bcdb84. It is recommended to upgrade the affected component.
Title GPAC downloader.c wait_for_header_and_parse out-of-bounds
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:45:13.312Z

Reserved: 2026-09-16T12:15:02.248Z

Link: CVE-2026-92475

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-16T20:17:48.780

Modified: 2026-09-22T16:18:12.013

Link: CVE-2026-92475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:30:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read