PT-2026-26668 · Gpac · Gpac
Xuemian168
·
Published
2026-03-20
·
Updated
2026-03-21
·
CVE-2026-33144
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GPAC versions prior to commit 86b0e36
Description
GPAC is an open-source multimedia framework. A heap-based buffer overflow (write) issue exists in GPAC MP4Box within the
gf xml parse bit sequence bs function in utils/xml bin custom.c when processing a crafted NHML file containing malicious (BitSequence) elements. An attacker can exploit this by providing a specially crafted NHML file, causing an out-of-bounds write on the heap.Recommendations
Update GPAC to commit 86b0e36 or later.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gpac