HIGH
CVE-2026-93331
CVSS
7.3
Description
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. The affected component should be upgraded.
Weakness (CWE)
CWE-119
Memory Buffer Bounds Error
CWE-125
Out-of-bounds Read
EPSS Score
0.31%
Probability of exploitation in next 30 days
24.5th percentile
References
https://github.com/gpac/gpac/
https://github.com/gpac/gpac/commit/6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68
https://github.com/gpac/gpac/issues/3868
https://github.com/gpac/gpac/releases/tag/abi-16.26
https://vuldb.com/cve/CVE-2026-93331
https://vuldb.com/submit/942834
https://vuldb.com/vuln/406641
https://vuldb.com/vuln/406641/cti
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.