CVE-2026-92475

Source
https://cve.org/CVERecord?id=CVE-2026-92475
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92475.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92475
Downstream
Published
2026-09-16T19:45:09Z
Modified
2026-09-19T08:03:29Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
GPAC downloader.c wait_for_header_and_parse out-of-bounds
Details

A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. Upgrading to version abi-16.26 will fix this issue. Patch name: c74a3065038ede35c1c7b75fa493a69ef6bcdb84. It is recommended to upgrade the affected component.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92475.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "26.08-DEV"
                },
                {
                    "last_affected": "26.08-DEV"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
abi-12
abi-13
abi-14
abi-15
abi-16
abi-12.*
abi-12.16
abi-12.17
abi-12.18
abi-12.19
abi-12.20
abi-12.21
abi-12.22
abi-12.23
abi-12.24
abi-12.25
abi-12.26
abi-12.27
abi-13.*
abi-13.0
abi-14.*
abi-14.0
abi-15.*
abi-15.0
abi-15.1
abi-15.2
abi-16.*
abi-16.10
abi-16.11
abi-16.13
abi-16.14
abi-16.15
abi-16.16
abi-16.17
abi-16.18
abi-16.19
abi-16.2
abi-16.20
abi-16.21
abi-16.22
abi-16.23
abi-16.24
abi-16.25
abi-16.3
abi-16.4
abi-16.5
abi-16.6
abi-16.7
abi-16.8
abi-16.9
testtag0.*
testtag0.1
v0.*
v0.5.2
v0.6.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v2.*
v2.0.0
v2.2.0
v26.*
v26.02.0
v26.07.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92475.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "113532806442412209285326814569378924216",
                "222812815322165835615870913078873632935",
                "33285251936288400358669859075314338749",
                "13163536750990058534122683155383610281"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92475-10810caa",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/utils/downloader.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "196886524512190210561644223134175559641",
            "length": 589
        },
        "id": "CVE-2026-92475-1181845f",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/scenegraph/svg_attributes.c",
            "function": "svg_parse_one_style"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "51560382315540796508071145270770864514",
                "299584943590148898848051083817706791310",
                "22227591907130438623480013530158288683",
                "248529780242760136911877051428931092771"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92475-1fd29817",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/scenegraph/svg_attributes.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "243119197061636433200301779569191187294",
            "length": 3683
        },
        "id": "CVE-2026-92475-34c8f024",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/ietf/rtsp_command.c",
            "function": "gf_rtsp_get_command"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "107350727320694322807994971698793417223",
            "length": 26543
        },
        "id": "CVE-2026-92475-3fa35ab5",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/utils/downloader.c",
            "function": "wait_for_header_and_parse"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "62707137233316576658252687246767978108",
            "length": 910
        },
        "id": "CVE-2026-92475-4c2c4a5f",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/scenegraph/svg_js.c",
            "function": "dom_imp_has_feature"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "251058682474571903719220944953214018764",
                "274305576212320113555123970018127744932",
                "22980713520287186866348148490336159719",
                "187803518009404277477222399844737598640"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92475-52f0d4f6",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/scenegraph/vrml_js.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "131369589426234630541994705755662674085",
            "length": 939
        },
        "id": "CVE-2026-92475-79e760e9",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/compositor/svg_text.c",
            "function": "gf_compositor_svg_set_font"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "213591073579912458201964938799450362502",
                "206742139907724147523589896325138583201",
                "334974963145773877431850241460944593833",
                "6141300554063540794674451773730229389"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92475-b3b3dd75",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/compositor/svg_text.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "147632837417409568653236730773453098398",
                "80884617702328382898730140093766994122",
                "111197518715849333113232612366716526597",
                "10509302071519437524579370489339118951"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92475-c12c2d14",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/ietf/rtsp_command.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "15731257482622681997496028783970097682",
                "306555504627961798852220948861385437170",
                "182704798123026385702323784070193236947",
                "283841469201846941915763187536617166605",
                "152681621541469828564337107627252641999",
                "54570618305940312664744806976851241871",
                "311459596702918449929541403427292468932"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92475-c90d1e8d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/scenegraph/svg_js.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "94980271103232212179743166530820929922",
            "length": 3005
        },
        "id": "CVE-2026-92475-ca2dcb2e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/scenegraph/vrml_js.c",
            "function": "JSScript_LoadVRML"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "162566321804205682532887724003987630993",
            "length": 6377
        },
        "id": "CVE-2026-92475-dd8a64fb",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/bifs/script_enc.c",
            "function": "SFE_NextToken"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "74041732072106962442361374769382996705",
                "223897397295402791934883085272157487392",
                "234991499591902847473122070930528095655",
                "138613277830233999215543941469805238478"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92475-e431e321",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/c74a3065038ede35c1c7b75fa493a69ef6bcdb84",
        "target": {
            "file": "src/bifs/script_enc.c"
        }
    }
]
vanir_signatures_modified
"2026-09-19T08:03:29Z"