{"id":"CVE-2026-35203","summary":"ZLMediaKit VP9 RTP Parser Out-of-Bounds Read","details":"ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fields from the RTP payload based on flag bits in the first byte, without verifying that sufficient data exists in the buffer. A crafted VP9 RTP packet with a 1-byte payload (0xFF, all flags set) causes the parser to read past the end of the allocated buffer, resulting in a heap-buffer-overflow. This vulnerability is fixed with commit 435dcbcbbf700fd63b2ca9eac6cef3b5ea75169d.","aliases":["GHSA-gxr3-fwc7-q99h"],"modified":"2026-09-28T08:01:57.808698Z","published":"2026-04-06T19:54:45.052Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35203.json","unresolved_ranges":[{"extracted_events":[{"fixed":"435dcbcbbf700fd63b2ca9eac6cef3b5ea75169d"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-125"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35203.json"},{"type":"ADVISORY","url":"https://github.com/ZLMediaKit/ZLMediaKit/security/advisories/GHSA-gxr3-fwc7-q99h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35203"},{"type":"FIX","url":"https://github.com/ZLMediaKit/ZLMediaKit/commit/435dcbcbbf700fd63b2ca9eac6cef3b5ea75169d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zlmediakit/zlmediakit","events":[{"introduced":"0"},{"fixed":"435dcbcbbf700fd63b2ca9eac6cef3b5ea75169d"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35203.json","vanir_signatures_modified":"2026-09-28T08:01:57Z","vanir_signatures":[{"digest":{"length":766,"function_hash":"258717882410040396913537876958198852610"},"id":"CVE-2026-35203-cd64b282","signature_type":"Function","signature_version":"v1","source":"https://github.com/zlmediakit/zlmediakit/commit/435dcbcbbf700fd63b2ca9eac6cef3b5ea75169d","target":{"function":"VP9RtpDecoder::decodeRtp","file":"ext-codec/VP9Rtp.cpp"},"deprecated":false},{"digest":{"function_hash":"281722551504849388086115956845544698495","length":2068},"id":"CVE-2026-35203-e3862a75","signature_type":"Function","signature_version":"v1","source":"https://github.com/zlmediakit/zlmediakit/commit/435dcbcbbf700fd63b2ca9eac6cef3b5ea75169d","target":{"file":"ext-codec/VP9Rtp.cpp","function":"RTPPayloadVP9::parse"},"deprecated":false},{"source":"https://github.com/zlmediakit/zlmediakit/commit/435dcbcbbf700fd63b2ca9eac6cef3b5ea75169d","target":{"file":"ext-codec/VP9Rtp.cpp"},"deprecated":false,"digest":{"line_hashes":["68727550765386503878554445499225644279","225772907824085979473977862366414526751","32124426029648688871090975236460002104","287902914284095827066290317120462426179","322991568468495192210273473194322542275","228965578513133427122550520235974175048","84201656213927853850719287413084173046","222810554772149594249931824643951398848","186299688038694628908513498196679041368","45043892198462049010397771383752295910","130623892824038841836777677012464944841","10222967381041982520286811613295750067","244666630687213779787886355592560770673","259127119718616719562665665957131127541","67809424293268704712902518799292358288","85900714123334670747338184631956946661","197157609517914394958651528904112889016","27104009338996721067732924929816731348","35367682741325860105763098807493553545","88903788424140303223589865508313700922","116335171822889953262804220794387937187","147186060393568674371329246704045326164","142700915461432063101325607920524793493","209091410753730314378891871935248979488","226950012846710873552457883385226013772","208655511415778722216382337062929568385","243165474168203649558950861144677317970","9941830407839498434842731905174432000","104614157264967930109953203515032559176","72729803239924559282659596130380412235","137722692271279093275911671130826889463","114253520917539108315545743141648173386","70789442259339208694702936893170309355","278821962580248219786790096113184522100","105447394672515931000016525382226620183","170514758158391482667956857907987783670","65271709797993156905327878581066820001","168555503036284864212138342652735825488","147196799884412713301752372648360442778","305164602788622487838813931209926086868","41664910034856314828494939222670206629","24098045174178990253434989669756315484","134142255655048276548202295062475187274","155640738141574900500572502493630099140","240581480665562005004010934793919867662","185022940454940613690569018235053100185","231586490819788768562929622051092659746","225475946605499512776430603292131693211","199944867172363642734330597666888713162","300375608645298731051614345077943252110","12584312955103328694711549506948441472","311103465720484973251291180222258998624","96210548902809984854315775206359920380","51945665789283038517064773277824627443","127270496637856942280120407835450587749","164598106071458215414190283088040939749","2760119766038298010692436314928934950","234830956442235235751348872527677151630"],"threshold":0.9},"id":"CVE-2026-35203-eed95cf6","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}