Geovision · Geowebplayer · CVE-2026-57277
**Name of the Vulnerable Software and Affected Versions**
GeoWebPlayer (affected versions not specified)
**Description**
The GeoWebPlayer websocket server, used as an addon for GeoVision software such as GV-VMS and GV-Cloud, contains a memory corruption issue. The `handle connection info` function, which processes the `connectionInfo` command, fails to enforce length limits when copying attacker-controlled JSON strings into fixed-size buffers. This occurs through manual byte-by-byte loops, specifically affecting the key field, which can lead to a buffer overflow.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.