PT-2026-25559 · Gpac · Gpac+1

Peterx

·

Published

2026-01-01

·

Updated

2026-03-16

·

CVE-2026-4185

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GPAC versions up to 2.5-DEV-rev2167-gcc9d617c0-master
Description A flaw exists in GPAC that involves a stack-based buffer overflow within the swf def bits jpeg function, located in the src/scene manager/swf parse.c file of the MP4Box component. The issue stems from the manipulation of the szName argument. This can be exploited remotely, and details of the exploit are publicly available.
Recommendations Apply patch 8961c74f87ae3fe2d3352e622f7730ca96d50cf1 to remediate this issue.

Exploit

Fix

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04704
CVE-2026-4185

Affected Products

Gpac
Mp4Box