A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. Upgrading to version abi-16.26 will fix this issue. Patch name: c74a3065038ede35c1c7b75fa493a69ef6bcdb84. It is recommended to upgrade the affected component.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92475.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "26.08-DEV"
},
{
"last_affected": "26.08-DEV"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92475.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"113532806442412209285326814569378924216",
"222812815322165835615870913078873632935",
"33285251936288400358669859075314338749",
"13163536750990058534122683155383610281"
],
"threshold": 0.9
},
"id": "CVE-2026-92475-10810caa",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/utils/downloader.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "196886524512190210561644223134175559641",
"length": 589
},
"id": "CVE-2026-92475-1181845f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/scenegraph/svg_attributes.c",
"function": "svg_parse_one_style"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"51560382315540796508071145270770864514",
"299584943590148898848051083817706791310",
"22227591907130438623480013530158288683",
"248529780242760136911877051428931092771"
],
"threshold": 0.9
},
"id": "CVE-2026-92475-1fd29817",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/scenegraph/svg_attributes.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "243119197061636433200301779569191187294",
"length": 3683
},
"id": "CVE-2026-92475-34c8f024",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/ietf/rtsp_command.c",
"function": "gf_rtsp_get_command"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "107350727320694322807994971698793417223",
"length": 26543
},
"id": "CVE-2026-92475-3fa35ab5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/utils/downloader.c",
"function": "wait_for_header_and_parse"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "62707137233316576658252687246767978108",
"length": 910
},
"id": "CVE-2026-92475-4c2c4a5f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/scenegraph/svg_js.c",
"function": "dom_imp_has_feature"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"251058682474571903719220944953214018764",
"274305576212320113555123970018127744932",
"22980713520287186866348148490336159719",
"187803518009404277477222399844737598640"
],
"threshold": 0.9
},
"id": "CVE-2026-92475-52f0d4f6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/scenegraph/vrml_js.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "131369589426234630541994705755662674085",
"length": 939
},
"id": "CVE-2026-92475-79e760e9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/compositor/svg_text.c",
"function": "gf_compositor_svg_set_font"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"213591073579912458201964938799450362502",
"206742139907724147523589896325138583201",
"334974963145773877431850241460944593833",
"6141300554063540794674451773730229389"
],
"threshold": 0.9
},
"id": "CVE-2026-92475-b3b3dd75",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/compositor/svg_text.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"147632837417409568653236730773453098398",
"80884617702328382898730140093766994122",
"111197518715849333113232612366716526597",
"10509302071519437524579370489339118951"
],
"threshold": 0.9
},
"id": "CVE-2026-92475-c12c2d14",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/ietf/rtsp_command.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"15731257482622681997496028783970097682",
"306555504627961798852220948861385437170",
"182704798123026385702323784070193236947",
"283841469201846941915763187536617166605",
"152681621541469828564337107627252641999",
"54570618305940312664744806976851241871",
"311459596702918449929541403427292468932"
],
"threshold": 0.9
},
"id": "CVE-2026-92475-c90d1e8d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/scenegraph/svg_js.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "94980271103232212179743166530820929922",
"length": 3005
},
"id": "CVE-2026-92475-ca2dcb2e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/scenegraph/vrml_js.c",
"function": "JSScript_LoadVRML"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "162566321804205682532887724003987630993",
"length": 6377
},
"id": "CVE-2026-92475-dd8a64fb",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/bifs/script_enc.c",
"function": "SFE_NextToken"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"74041732072106962442361374769382996705",
"223897397295402791934883085272157487392",
"234991499591902847473122070930528095655",
"138613277830233999215543941469805238478"
],
"threshold": 0.9
},
"id": "CVE-2026-92475-e431e321",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
"target": {
"file": "src/bifs/script_enc.c"
}
}
]
"2026-09-19T08:03:29Z"