OCTOBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-61714

HIGH · CVSS 7.8 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-11

CyberRota Analysis

AI-Generated

FluidSynth versions 2.2.4 to 2.5.6 are vulnerable due to improper handling of MIDI channel configurations, allowing out-of-bounds memory access that can lead to undefined behavior and potential compromise of system confidentiality, integrity, or availability. Users configuring the synth.midi-channels above the default of 16 should prioritize upgrading to version 2.5.6 to mitigate this risk. This vulnerability is particularly critical for developers and organizations utilizing FluidSynth in production environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61714
Severity
HIGH
CVSS
7.8
EPSS
0.14%

Original NVD Description

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, or availability. No crafted MIDI file is required because the unsafe condition is created by the channel-count configuration itself. Keeping synth.midi-channels at its default value of 16 avoids the vulnerable path. This issue is fixed in version 2.5.6.