Impact
The vulnerability resides in GPAC’s downloader component, where manipulating the Content-Range header during a media download triggers an out-of-bounds read in the function wait_for_header_and_parse. This flaw can allow an attacker with local access to read memory beyond the intended buffer, potentially leaking sensitive data from the process. The CVE description explicitly notes that the exploit requires local privilege and that it has been made publicly available, but the flaw does not provide a pathway to execute code or affect remote systems.
Affected Systems
Affected versions include GPAC 26.08‑DEV. The recommended fix is to upgrade to the abi‑16.26 release or any later build that incorporates commit c74a3065038ede35c1c7b75fa493a69ef6bcdb84. No other vendor or product versions are listed, and the fix is specific to GPAC’s upstream repository.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact, while the EPSS score of less than 1 % reflects a very low likelihood of exploitation in the wild. The vulnerability is not catalogued in CISA’s KEV, further suggesting limited exploitation activity. Because the attack requires local access, a threat actor must first gain the ability to run GPAC on the target machine, after which the manipulated Content-Range header can drive the out‑of‑bounds read.
OpenCVE Enrichment