{"id":"CVE-2026-102296","summary":"ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response","details":"ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Attackers can send crafted HTTP responses with oversized status messages, Connection headers, Content-Type values, or multipart boundaries to corrupt parser state and crash the capture process or corrupt memory.","aliases":["GHSA-93j4-rcp9-9jx6"],"modified":"2026-10-01T08:05:50.370369Z","published":"2026-09-28T22:00:19.143Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-120"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102296.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102296.json"},{"type":"ADVISORY","url":"https://github.com/ZoneMinder/zoneminder/releases/tag/1.38.4"},{"type":"ADVISORY","url":"https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-93j4-rcp9-9jx6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102296"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/zoneminder-before-1.38.4-buffer-overflow-via-http-camera-response"},{"type":"FIX","url":"https://github.com/ZoneMinder/zoneminder/commit/2596e5fb64c0348e615577b0ab08dc38b6dc6ed8"},{"type":"FIX","url":"https://github.com/ZoneMinder/zoneminder/commit/813bf6f1a3ffc92c163352f2480477ba571fca5b"},{"type":"PACKAGE","url":"https://github.com/ZoneMinder/zoneminder"},{"type":"ARTICLE","url":"https://github.com/ZoneMinder/zoneminder/blob/1.38.3/src/zm_remote_camera_http.cpp#L736"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zoneminder/zoneminder","events":[{"introduced":"0"},{"fixed":"b2192aa427fcdeec797d1b4d0605e6d7f2661b12"},{"fixed":"2596e5fb64c0348e615577b0ab08dc38b6dc6ed8"},{"fixed":"813bf6f1a3ffc92c163352f2480477ba571fca5b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.38.4"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["1.38.3","1.38.2","1.38.1","1.38.0","1.36.0","1.34.0","1.32.3","v1.26.3","v1.26.2","v1.26.1","v1.26.0","v1.25"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102296.json","vanir_signatures_modified":"2026-10-01T08:05:50Z","vanir_signatures":[{"source":"https://github.com/zoneminder/zoneminder/commit/2596e5fb64c0348e615577b0ab08dc38b6dc6ed8","target":{"file":"src/zm_utils.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["318274859869415830068103415624293312247","334833343558071921453227182515748853934","150284697144370788393712577906644997666","289537055790189100505142228241013196798","112204226091715247099172332888093104034","282182230225214968563051896556788356855","250403597381704747942011619795816990848"]},"id":"CVE-2026-102296-0ccbe6af","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["67887147935824926307155039922168188486","107928334680861794666658732697474524366","254607383426779977274680637657345665584","279982106185350397257144789304946533896","337755435867055211407772722883050483260","64641873675897995243246803341902708457","315806956979316447789645953514244257593","307219685409868039540787265083023311452","167220103357309295019968051083599957793","77467691078044032616262342498779884588","106782560294602265590148680744508879997","205066109428335952598408443337667735774","184556982031997635267310565943264042742","128599025615605301977831439997504313126","121313715080224662916349830672409262176","285961284378345534606753199527957111693","328469725607491945808802208943288831575","94785297719133787174005701584121008854","27005919430413098127785505865774116805","138580750652928032448127143248529029665","283464442600206769636634578626116131164","47639559549218741353658110237517411349","89582187051977064414592977547806658790","31806296257049614891667343078131134078","94206070469043987754176540480121409229","332428289649338329226189339088253696936","140129995193316107455275453116854092920","288108257267482632835864917710931659114","301773149018779348666276704886717724350","68102347040500953247805222417141597824","323615110933657210927173052927590336608","307005892893350485732695792108927037191","113364056494772912533068622280241874409","171723134388649195668344781062216950258","107107203094836478894939735566834335692","234421028750024914998058621363151940655","132613991050054866907246593347120327915"],"threshold":0.9},"id":"CVE-2026-102296-11a91700","signature_type":"Line","signature_version":"v1","source":"https://github.com/zoneminder/zoneminder/commit/2596e5fb64c0348e615577b0ab08dc38b6dc6ed8","target":{"file":"src/zm_remote_camera_http.cpp"}},{"target":{"file":"src/zm_remote_camera_http.cpp"},"deprecated":false,"digest":{"line_hashes":["67887147935824926307155039922168188486","107928334680861794666658732697474524366","254607383426779977274680637657345665584","279982106185350397257144789304946533896","337755435867055211407772722883050483260","64641873675897995243246803341902708457","315806956979316447789645953514244257593","307219685409868039540787265083023311452","167220103357309295019968051083599957793","77467691078044032616262342498779884588","106782560294602265590148680744508879997","205066109428335952598408443337667735774","184556982031997635267310565943264042742","128599025615605301977831439997504313126","121313715080224662916349830672409262176","285961284378345534606753199527957111693","328469725607491945808802208943288831575","94785297719133787174005701584121008854","27005919430413098127785505865774116805","138580750652928032448127143248529029665","283464442600206769636634578626116131164","47639559549218741353658110237517411349","89582187051977064414592977547806658790","31806296257049614891667343078131134078","94206070469043987754176540480121409229","332428289649338329226189339088253696936","140129995193316107455275453116854092920","288108257267482632835864917710931659114","301773149018779348666276704886717724350","68102347040500953247805222417141597824","323615110933657210927173052927590336608","307005892893350485732695792108927037191","113364056494772912533068622280241874409","171723134388649195668344781062216950258","107107203094836478894939735566834335692","234421028750024914998058621363151940655","132613991050054866907246593347120327915"],"threshold":0.9},"id":"CVE-2026-102296-1c6ae34f","signature_type":"Line","signature_version":"v1","source":"https://github.com/zoneminder/zoneminder/commit/813bf6f1a3ffc92c163352f2480477ba571fca5b"},{"source":"https://github.com/zoneminder/zoneminder/commit/2596e5fb64c0348e615577b0ab08dc38b6dc6ed8","target":{"file":"src/zm_remote_camera_http.cpp","function":"RemoteCameraHttp::GetResponse"},"deprecated":false,"digest":{"function_hash":"246641697770703966621408618087513263574","length":17349},"id":"CVE-2026-102296-4c0072a0","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"246641697770703966621408618087513263574","length":17349},"id":"CVE-2026-102296-ea32d2e7","signature_type":"Function","signature_version":"v1","source":"https://github.com/zoneminder/zoneminder/commit/813bf6f1a3ffc92c163352f2480477ba571fca5b","target":{"file":"src/zm_remote_camera_http.cpp","function":"RemoteCameraHttp::GetResponse"}},{"deprecated":false,"digest":{"line_hashes":["318274859869415830068103415624293312247","334833343558071921453227182515748853934","150284697144370788393712577906644997666","289537055790189100505142228241013196798","112204226091715247099172332888093104034","282182230225214968563051896556788356855","250403597381704747942011619795816990848"],"threshold":0.9},"id":"CVE-2026-102296-f77c0d86","signature_type":"Line","signature_version":"v1","source":"https://github.com/zoneminder/zoneminder/commit/813bf6f1a3ffc92c163352f2480477ba571fca5b","target":{"file":"src/zm_utils.h"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"}]}