๐Ÿ” CVE Alert

CVE-2026-61714

HIGH 7.8

FluidSynth: Heap Buffer Overflow in MIDI Player

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, or availability. No crafted MIDI file is required because the unsafe condition is created by the channel-count configuration itself. Keeping synth.midi-channels at its default value of 16 avoids the vulnerable path. This issue is fixed in version 2.5.6.

CWE CWE-122 CWE-125 CWE-787
Vendor fluidsynth
Product fluidsynth
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for fluidsynth fluidsynth

Be the first to know when new high vulnerabilities affecting fluidsynth fluidsynth are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

FluidSynth / fluidsynth
>= 2.2.4, < 2.5.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-976m-35rw-h3m6 github.com: https://github.com/FluidSynth/fluidsynth/commit/772702e00cc6acc7c607efb40283e2269211effc github.com: https://github.com/FluidSynth/fluidsynth/releases/tag/v2.5.6