Out-of-Bounds Read Vulnerability in GPAC Affects Multiple Versions
CVE-2026-79514

6.5MEDIUM

Key Information:

Vendor

GPAC

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-79514?

An out-of-bounds read vulnerability has been identified in the gf_dm_data_received function of GPAC version 26.07.0. This flaw allows an attacker to craft a malicious HTTP request that can trigger a Denial of Service (DoS) condition, disrupting access to the service. This issue has been addressed in the recent fix identified in a specific commit on the official GPAC GitHub repository.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.