{"id":"CVE-2026-92399","summary":"GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow","details":"A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.26 is able to mitigate this issue. This patch is called 37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12. Upgrading the affected component is recommended.","modified":"2026-09-18T08:10:18.755390Z","published":"2026-09-16T16:15:08.672Z","database_specific":{"cwe_ids":["CWE-119","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92399.json","cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/gpac/gpac/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92399.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92399"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-92399"},{"type":"ADVISORY","url":"https://vuldb.com/submit/940250"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/405551"},{"type":"REPORT","url":"https://github.com/gpac/gpac/issues/3860"},{"type":"REPORT","url":"https://vuldb.com/vuln/405551/cti"},{"type":"FIX","url":"https://github.com/gpac/gpac/commit/37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12"},{"type":"FIX","url":"https://github.com/gpac/gpac/releases/tag/abi-16.26"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/31208030/poc_rmt_ws_malicious_frame.py"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gpac/gpac","events":[{"introduced":"a07cbfff238a331233e11e916f9fb185d5da8604"},{"fixed":"37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12"},{"fixed":"c1a7cf55f59ef7954939c44f6b24b95c54469214"}],"database_specific":{"extracted_events":[{"introduced":"26.07.0"},{"last_affected":"26.07.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["26.07.0","abi-16.25","abi-16.24","abi-16.23","abi-16.22","v26.07.0"],"database_specific":{"vanir_signatures":[{"target":{"file":"src/utils/rmt_ws.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["270395094011190084658753405103484577409","166270095178778989230445956178718880561","305238990725512740394269618140737979835","250134317023930464039462420125309642271","208980771966711693305413306147563988077","144406941129539498280417551003194796801","50346789963063025339067420089289553853","319041155311837747112197280770453200948","335282667009757390456955123510043906145","280937728979152295577789304227767489204","292077008852201610868301411416028906049","153761557206386505805494466583349845420","184719081481429025268124268235257624006","338011553901935451224896099583885217264","86132515388389824589382742976009898144","236768225032545892445664161425516711196","62616554626504317616826296346474108429","155286010825778827379556718321033903199"]},"id":"CVE-2026-92399-c3096132","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12"},{"deprecated":false,"digest":{"function_hash":"40385034327597556048692288610652696411","length":2902},"id":"CVE-2026-92399-e173d7b2","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12","target":{"file":"src/utils/rmt_ws.c","function":"rmt_client_handle_ws_frame"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92399.json","vanir_signatures_modified":"2026-09-18T08:10:18Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}