PT-2026-38628 · Gpac · Gpac

Lucian-2333

·

Published

2026-05-08

·

Updated

2026-05-10

·

CVE-2026-8124

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GPAC versions prior to 26.02.0
Description A flaw in the sidx box read() function within the src/isomedia/box code base.c file allows for the allocation of resources through manipulation. This issue requires local access to be exploited.
Recommendations Install the patch identified as 442e2299530138d8f874fd885c565ba98a6318ba.

Exploit

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8124

Affected Products

Gpac