Description

ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fields from the RTP payload based on flag bits in the first byte, without verifying that sufficient data exists in the buffer. A crafted VP9 RTP packet with a 1-byte payload (0xFF, all flags set) causes the parser to read past the end of the allocated buffer, resulting in a heap-buffer-overflow. This vulnerability is fixed with commit 435dcbcbbf700fd63b2ca9eac6cef3b5ea75169d.

INFO

Published Date :

2026-04-06T19:54:45.052Z

Last Modified :

2026-04-06T19:54:45.052Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-35203 vulnerability.

Vendors Products
Zlmediakit
  • Zlmediakit
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-35203.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact