CVE-2026-79113
Received Received - Intake

Heap-based Buffer Overflow in OpenAPV

Vulnerability report for CVE-2026-79113, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: MITRE

Description

OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
academysoftwarefoundation openapv to 1.1.1.0 (exc)
academysoftwarefoundation openapv 1.1.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-79113 is a heap-based buffer overflow in the openAPV library's read_bitstream function, specifically affecting version 0.3.0.0. The vulnerability occurs when processing a maliciously crafted input file, causing a write operation beyond allocated heap memory. This leads to immediate program termination due to memory corruption detected by AddressSanitizer.

Detection Guidance

To detect this vulnerability, monitor for crashes or errors when processing APV files using openAPV version 0.3.0.0. Use AddressSanitizer (ASAN) to detect heap-buffer-overflows by running the oapv_app_dec command with a malformed input file like poc_au_size_overflow.apv. Check for ASAN error messages indicating a 1-byte write beyond heap memory.

Impact Analysis

The vulnerability can cause program crashes or unexpected behavior when processing malicious files. It may allow attackers to execute arbitrary code or disrupt services relying on openAPV for media processing. Systems using vulnerable versions could experience instability or security breaches.

Compliance Impact

This vulnerability, a heap-based buffer overflow in OpenAPV, could lead to program crashes or arbitrary code execution when processing malformed input files. Such instability may compromise data integrity and availability, which are critical for compliance with GDPR (data integrity and availability principles) and HIPAA (integrity and availability of protected health information). However, specific compliance impacts depend on system context and usage.

Mitigation Strategies

Upgrade openAPV to version 1.1.1.0 or later, which includes fixes for buffer overflows and integer overflows. Apply patches from pull request #226 to validate buffer sizes, TransCoeff ranges, and use unsigned arithmetic to prevent signed integer overflows. Enable release automation to ensure version consistency.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79113. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart