CVE-2026-49127
Published: 28 May 2026
Summary
CVE-2026-49127 is a high-severity Off-by-one Error (CWE-193) vulnerability in Github (inferred from references). Its CVSS base score is 8.6 (High).
Operationally, ranked at the 19.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Vulnerability
Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue…
more
two MPD commands referencing a malicious HTTP audio source to cause the unpack loop to write 1366 entries into a 1365-entry buffer, overwriting four bytes past the array boundary with three attacker-controlled bytes from an HTTP response body, resulting in daemon termination or potential code execution.
- CWE(s)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-33000
Affected Products
Threat picture
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Defense & controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.