CVE-2026-14324

Published: July 2, 2026Last modified: August 14, 2026

Description

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorADJACENT_NETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpipewireUnknown (0.3.60-r2)
25 LTSpipewireFixed (1.4.7-r1)
StreampipewireFixed (1.6.8-r0)

References

ON THIS PAGE