CVE-2026-9572
A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isome
CVSS
3.3
Bajo
EPSS
0.2%
p6
KEV
—
Exploit Today
2
0-100
Publicado: 26 may 2026 · Última mod.: 23 jul 2026 · CWE-401 · CWE-404
0.2%EPSS · 30 días0.2%
2026-07-042026-07-31
A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of the argument cat leads to memory leak. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The name of the patch is e79c5cbe8b3fed27f4854ec229457d30c96206f1. It is best practice to apply a patch to resolve this issue.
- github.comhttps://github.com/gpac/gpac/
- github.comhttps://github.com/gpac/gpac/commit/e79c5cbe8b3fed27f4854ec229457d30c96206f1
- github.comhttps://github.com/gpac/gpac/issues/3557
- github.comhttps://github.com/user-attachments/files/27270415/poc.zip
- vuldb.comhttps://vuldb.com/submit/817137
- vuldb.comhttps://vuldb.com/vuln/365631
- vuldb.comhttps://vuldb.com/vuln/365631/cti
- github.comhttps://github.com/gpac/gpac/issues/3557
- vuldb.comhttps://vuldb.com/submit/817137
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-12932—28.0%
——8A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets3dCVE-2026-674377.5 ALT28.1%
——8OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. This issue is fixed in version 3000.17.0.3dCVE-2026-674305.3 MED21.4%
——6MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by default, so repeated initialize requests retain unbounded ServerSession objects and can exhaust process memory. This issue is fixed in version 0.23.0.3dCVE-2026-581757.5 ALT36.3%
——11Apache Traffic Server leaks memory when handling HostDB SRV records.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.1dCVE-2026-671837.5 ALT29.4%
——9TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are never freed due to missing destructors and unreachable delete calls, causing worker resident memory to grow monotonically by approximately 20 to 28 kB per request until the worker process is killed.3dCVE-2026-175015.3 MED34.5%
——10A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes uncontrolled recursion. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.4d