Skip to content
Critical Heap Overflow Vulnerability in GPAC WebSocket Handler

Critical Heap Overflow Vulnerability in GPAC WebSocket Handler

First seen 17 Sep 2026, 01:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 03:51 UTC
  • CVE-2026-92399 affects GPAC 26.07.0, enabling remote exploitation.
  • Attackers can trigger a heap overflow via malformed WebSocket frames.
  • Immediate patching to version abi-16.26 is critical to mitigate risks.

A heap buffer overflow vulnerability (CVE-2026-92399) was discovered in GPAC version 26.07.0, affecting the rmt_client_handle_ws_frame function. This vulnerability allows remote attackers to exploit the WebSocket Handler by sending malformed frames, potentially leading to crashes or arbitrary code execution. The flaw arises from improper handling of large payload sizes, causing memory allocation errors. The vulnerability is confirmed to be exploitable, with a proof of concept available. Systems running internet-facing media services that utilize WebSocket are particularly at risk. Upgrading to version abi-16.26 is recommended to mitigate the issue. The vulnerability was publicly disclosed on September 16, 2026, and is treated as a high-priority exposure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-92399 published
A heap buffer overflow vulnerability in GPAC was publicly disclosed, affecting version 26.07.0.
Redpacketsecurity
2026-09-17
Vulnerability details confirmed
Details of the heap overflow vulnerability were confirmed with AI-based analysis tools, highlighting the exploitability and potential impacts.
github.com
2026-09-17
Mitigation recommendations issued
Security advisories recommend immediate upgrade to mitigate the vulnerability, treating it as a high-priority issue.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track Ubuntu and CVE-2026-92399 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed