OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-88376

HIGH · CVSS 7.5 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Bento4 version 1.6.0.0 is vulnerable to an integer underflow in the AP4_AvccAtom::Create() and AP4_HvccAtom::Create() functions, triggered by specially crafted MP4 files with improperly declared atom sizes. This vulnerability can lead to incorrect buffer allocations, resulting in application crashes and potential denial of service. Organizations using Bento4 for media processing should prioritize addressing this issue to maintain service availability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88376
Severity
HIGH
CVSS
7.5
EPSS
0.39%

Original NVD Description

Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can cause the payload-size calculation to wrap to a large unsigned value. The resulting invalid buffer allocation and copy operations can cause application termination, leading to denial of service.