VulnSea

GPAC vulnerabilities

CVEs whose affected-version data names the GPAC package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

37 CVEsRSS

CVE-2026-90578Medium· 5.3PoC
1w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local e…

TwilightEPSS 0.16%via NVD
CVE-2026-90577Medium· 5.3PoC
1w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffe…

TwilightEPSS 0.17%via NVD
CVE-2026-90576Low· 3.3PoC
1w ago

A security vulnerability has been detected in GPAC up to f1219cde

A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The…

TwilightEPSS 0.16%via NVD
CVE-2026-90573Low· 3.3PoC
1w ago

A vulnerability was identified in GPAC up to f1219cde

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is …

TwilightEPSS 0.12%via NVD
CVE-2026-79514Medium· 6.5PoC
1w ago

An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request

An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

Twilightgpac · gpacEPSS 0.29%via NVD
CVE-2026-79513Medium· 6.5PoC
1w ago

A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline

A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767…

Twilightgpac · gpacEPSS 0.21%via NVD
CVE-2026-79522Medium· 6.5PoC
1w ago

An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request

An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

Twilightgpac · gpacEPSS 0.29%via NVD
GPAC vulnerabilities (CVEs) — page 2 · VulnSea