AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19387

HIGH · CVSS 7.6 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A heap out-of-bounds write vulnerability in the GStreamer gst-plugins-bad adpcmdec element affects the decoding of IMA/DVI ADPCM audio, allowing crafted WAV files to exploit insufficient validation of sample counts in multi-channel streams. This can result in application crashes, denial of service, memory corruption, or even arbitrary code execution when handling untrusted media. Organizations utilizing GStreamer for media processing should prioritize patching this vulnerability to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19387
Severity
HIGH
CVSS
7.6
EPSS
0.24%

Original NVD Description

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.