Gpac · Gpac · CVE-2026-93331
**Name of the Vulnerable Software and Affected Versions**
GPAC version 26.08-DEV
**Description**
An out-of-bounds read can be triggered remotely in the RTP Depacketizer component. The issue exists within the `gf rtp parse ttxt()` function located in the `src/ietf/rtp depacketizer.c` file, where manipulation of the argument size allows for the memory read error.
**Recommendations**
Upgrade GPAC version 26.08-DEV to version abi-16.26.