Out-of-Bounds Read Vulnerability in GPAC RTP Depacketizer
CVE-2026-93331

6.9MEDIUM

Key Information:

Vendor

GPAC

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93331?

A vulnerability exists in the GPAC RTP Depacketizer, specifically in the gf_rtp_parse_ttxt function located in src/ietf/rtp_depacketizer.c. This flaw allows for manipulation of argument sizes, leading to potential out-of-bounds read conditions which can be exploited remotely. Users are advised to upgrade to version abi-16.26, where the issue has been resolved. The associated patch is identified as 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68.

Affected Version(s)

GPAC 26.08-DEV

GPAC abi-16.26

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dutch (VulDB User)
.