PT-2026-102392 · Unknown · Zoneminder

·

CVE-2026-102296

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZoneMinder versions prior to 1.38.4
Description A static buffer overflow exists in the RemoteCameraHttp::GetResponse() function. This issue allows malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Specifically, attackers can send crafted HTTP responses containing oversized status messages, Connection headers, Content-Type values, or multipart boundaries to corrupt the parser state, leading to memory corruption or a crash of the capture process.
Recommendations Update to version 1.38.4 or later.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102296
GHSA-93J4-RCP9-9JX6

Affected Products

Zoneminder