CVE-2026-8158
Received Received - Intake

Buffer Overflow in Signed Video Framework Validation Tools

Vulnerability report for CVE-2026-8158, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Axis Communications AB

Description

The Signed Video Framework contained aΒ  buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device'sΒ signed video functionality remains unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
axis signed_video_framework to 2.3.4 (exc)
axis signed_media_verifier to 1.0.1 (exc)
axis axis_file_player to 3.1.8.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow issue in the Signed Video Framework affecting versions 2.3.4 and earlier, Signed media verifier versions 1.0.1 and earlier, and Axis File Player versions 3.1.8.0 and earlier. It could cause applications using these tools to crash when validating signed content.

Detection Guidance

Check installed versions of affected software: Signed Video Framework <=2.3.4, Signed media verifier <=1.0.1, Axis File Player <=3.1.8.0. Use package managers like apt or yum to list versions. Monitor application crashes during signed content validation.

Impact Analysis

The vulnerability may cause applications relying on the Signed Video Framework to crash during the validation of signed content. However, the signed video functionality on AXIS OS devices remains unaffected.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. It is a buffer overflow issue in the Signed Video Framework that could cause applications to crash but does not involve unauthorized data access or disclosure. Compliance impact would depend on how the affected tools are used in a system.

Mitigation Strategies

Update to patched versions: Signed-Video-Framework 2.3.5, Signed media verifier 1.0.2, Axis File Player 3.1.9.0. Remove or restrict access to vulnerable tools used for signed content validation until updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8158. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart