A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amfstringnew of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as f412a33b9a84c2d1a9dee145a868feddbf64879e. A patch should be applied to remediate this issue. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82820.json",
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-122"
]
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "1.2.0"
},
{
"last_affected": "1.2.0"
},
{
"introduced": "1.2.1"
},
{
"last_affected": "1.2.1"
},
{
"introduced": "1.2.2"
},
{
"last_affected": "1.2.2"
}
]
}
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"310514777420173794807366857929631032940",
"244370841812237999735699935665842809825",
"128732334420010214190282016849375588116",
"101370302593737652182262194602810446547",
"251009801443111364011588183501236655053",
"130781754329986671525063898081549737686",
"159293484608031558171543201754742373418",
"43987466160122569819770566681973023583",
"85992325812327259723141091534380562807",
"73728616963582172539579608879150191070",
"99299901983208145384755733197203590256",
"165820954852985850711403580150185954695"
],
"threshold": 0.9
},
"id": "CVE-2026-82820-4aab8ce0",
"target": {
"file": "src/amf.c"
},
"source": "https://github.com/noirotm/flvmeta/commit/f412a33b9a84c2d1a9dee145a868feddbf64879e",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"297782582062901242244834457954230992243",
"7936062967026794509415722111970322622",
"122563071683213048106395023691305137802",
"8087127419057187517553055646896399794"
],
"threshold": 0.9
},
"id": "CVE-2026-82820-54b8b3bf",
"target": {
"file": "src/amf.h"
},
"source": "https://github.com/noirotm/flvmeta/commit/f412a33b9a84c2d1a9dee145a868feddbf64879e",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 928.0,
"function_hash": "264041650876922739760280910831815233974"
},
"id": "CVE-2026-82820-6ec970c0",
"target": {
"function": "amf_data_clone",
"file": "src/amf.c"
},
"source": "https://github.com/noirotm/flvmeta/commit/f412a33b9a84c2d1a9dee145a868feddbf64879e",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 531.0,
"function_hash": "281318379569081367423767149675183115732"
},
"id": "CVE-2026-82820-ae30346a",
"target": {
"function": "amf_string_new",
"file": "src/amf.c"
},
"source": "https://github.com/noirotm/flvmeta/commit/f412a33b9a84c2d1a9dee145a868feddbf64879e",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82820.json"
"2026-09-03T08:04:45Z"