{"id":"CVE-2026-103227","title":"A weakness has been identified in GPAC up to 26.07.0","summary":"A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","cwe":["CWE-119","CWE-120"],"product":"GPAC","affected":["GPAC 26.07"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T16:11:41.097","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103227","references":[{"url":"https://github.com/gpac/gpac/","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/commit/4c8e26f278ff63eec57968f7bc696f604bb0cffd","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/issues/3876","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/pull/3879","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/releases/tag/abi-16.26","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-103227","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/955033","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/411908","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/411908/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T15:07:05.386Z","slug":"CVE-2026-103227","body":"## Overview\n\nA weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. Upgrading to version abi-16.26 can resolve this issue. Patch name: 4c8e26f278ff63eec57968f7bc696f604bb0cffd. It is recommended to upgrade the affected component.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}