CVE-2026-3082 is a high-severity heap-based buffer overflow vulnerability in the GStreamer JPEG parser, specifically within its Huffman table processing, which allows remote attackers to execute arbitrary code on affected GStreamer installations. Exploitation requires user interaction, typically through processing a malicious JPEG file, but has low attack complexity. This flaw carries a CVSS score of 7.8 (HIGH), indicating a significant impact on confidentiality, integrity, and availability. While not yet listed in CISA's Known Exploited Vulnerabilities catalog, it is on a "Hot List" for critical concern; however, public exploit code is currently unavailable, and its EPSS score suggests a very low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.28.1CPE matchmatch criteria | cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.